|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: [TL-Security-Announce] Linux Kernel TLSA2000013-1
From: Gregory Neil Shapiro (gshapiro
SENDMAIL.ORG)Date: Wed Jun 28 2000 - 12:30:43 CDT
- Next message: Security: "Re: Possible root exploit in ISC DHCP client."
- Previous message: Cashdollar, Larry: "Re: sawmill5.0.21 path bug"
- In reply to: Roger Luethi: "[TL-Security-Announce] Linux Kernel TLSA2000013-1"
- Reply: Gregory Neil Shapiro: "Re: [TL-Security-Announce] Linux Kernel TLSA2000013-1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
rluethi> TurboLinux Security Announcement
rluethi> Package: kernel-2.2.15 and earlier
rluethi> Date: Monday June 19 17:45 PDT 2000
rluethi> TurboLinux Advisory ID#: TLSA2000013-1
rluethi> BugTraq ID#: 1322
rluethi> Credits: This vulnerability was discovered by Wojciech Purczynski.
rluethi> 1. Problem Summary
rluethi> Originally this security bug was reported by Sendmail. An unsafe
rluethi> fgets() usage in sendmail's mail.local exposes the setuid() security
rluethi> hole in the Linux kernel. This vunlnerability allows local users to
rluethi> obtain root privilege by exploiting setuid root applications.
This is completely incorrect. This problem had nothing to do with an
unsafe fgets(). There are no unsafe fgets() in sendmail or mail.local.
This was a bug in the Linux kernel, not in sendmail and not in mail.local.
Please correct your advisory and post an updated version.
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0 for non-commercial use
Comment: Processed by Mailcrypt 3.5.5, an Emacs/PGP interface
Charset: noconv
iQCVAwUBOVo2OnxLZ22gDhVjAQE4FwQArXGXsv0vC29SOQiEfetkaC94ByJfDkG6
CW+Ovjv9nc3ThbbpK7UR/+1ffD8Uw2fMDb5+07mffZO2Bhw4n3dZ7eyXwbFvpCT6
j05eDyVgkLxBhrrxjVKIeeNDQJPP+joxvfc11DlZzt1J1EuhWeHF6SSEzYJAajaN
5os5ccgee80=
=Y5Cs
-----END PGP SIGNATURE-----
- Next message: Security: "Re: Possible root exploit in ISC DHCP client."
- Previous message: Cashdollar, Larry: "Re: sawmill5.0.21 path bug"
- In reply to: Roger Luethi: "[TL-Security-Announce] Linux Kernel TLSA2000013-1"
- Reply: Gregory Neil Shapiro: "Re: [TL-Security-Announce] Linux Kernel TLSA2000013-1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]