OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Corel Linux 1.0 dosemu default configuration: Local root vuln
From: VaMPiRe, WHiTe (whitvampMINDLESS.COM)
Date: Fri Mar 03 2000 - 01:54:17 CST


On Thu, Mar 02, 2000 at 04:47:11AM +0000, suidSUID.KG(suidSUID.KG) wrote:
<snip>
: Summary:
:
: Local users can take advantage of a packaging and configuration
: error (which has been known and documented for a long time) to
: execute arbitrary commands as root.
:
: We see from the doc/README/SECURITY file as well as
: http://www.dosemu.org/docs/README/0.98/README-3.html
: written in 1997 that this configuration is bad.
<snip>

        Tested default configuration of dosemu on Slackware 7.0, no
vulnerability.

Regards,

-- 
    __      ______   ____
   /  \    /  \   \ /   / WHiTe VaMPiRe\Rem
   \   \/\/   /\   Y   /  whitevampiremindless.com
    \        /  \     /   http://www.projectgamma.com/
     \__/\  /    \___/    http://www.gammaforce.org/
          \/ "Silly hacker, root is for administrators."


  • application/pgp-signature attachment: stored