|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Redhat 6.2 dump command executes external program with suid priviledge
From: Christopher McCrory (chrismcc
PRICEGRABBER.COM)Date: Wed Nov 01 2000 - 10:05:41 CST
- Next message: Gerardo Richarte: "Re: Future of buffer overflows ?"
- Previous message: Dylan Griffiths: "Re: announcing PaX"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Hello...
This is the location for the latest version
ftp://ftp.sourceforge.net/pub/sourceforge/dump/
dump is no longer suid root.
I tested the short exploit on RedHat7 (dump-0.4b19-4) and was _not_
successful. Redhat7 does not ship dump suid root. I tested the exploit
on the latest version from sourceforge (dump-0.4b19-1) was was _not_
successful. An untested workaround would probably be to remove the suid
bit from /sbin/dump, but I haven't verified it as all my servers was
already running 0.4b19.
--Christopher McCrory "The guy that keeps the servers running" chrismcc
pricegrabber.com http://www.pricegrabber.com
"Linux: Because rebooting is for adding new hardware"
- Next message: Gerardo Richarte: "Re: Future of buffer overflows ?"
- Previous message: Dylan Griffiths: "Re: announcing PaX"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]