OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: mtr-0.41 root exploit
From: Kris Kennaway (krisFREEBSD.ORG)
Date: Mon Apr 24 2000 - 16:02:19 CDT


On Mon, 24 Apr 2000, Przemyslaw Frasunek wrote:

> /* (c) 2000 babcia padlina / buffer0verfl0w security (www.b0f.com) */
> /* freebsd mtr-0.41 local root exploit */

Oh, please. This was fixed on

revision 1.21
date: 2000/03/07 23:49:01; author: billf; state: Exp; lines: +10 -10
SECURITY UPGRADE: 0.42 addresses the setuid dropping issues addressed on
BugTraq by Viktor Fougstedt.
----------------------------

after being reported here shortly beforehand. I even released a security
advisory for it.

Kris

----
In God we Trust -- all others must submit an X.509 certificate.
    -- Charles Forsythe <forsythealum.mit.edu>