OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Rodrigo Barbosa (rodrigobbh.conectiva.com.br)
Date: Wed Dec 05 2001 - 09:36:59 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Conectiva Linux does not ship with agetty.

    On Tue, Dec 04, 2001 at 03:55:00PM -0500, KF wrote:
    > How about the agetty? I have seen one other agetty core dump in the
    > list I think... a slack 7.1 box. Most people reported an error with
    > agetty `perl -e 'print "A" x 9000'` one did core though
    >
    > my agetty required an addtional argument.
    > agetty `perl -e 'print "A" x 9000'` `perl -e 'print "A" x 9000'`
    >
    >
    > Rodrigo Barbosa wrote:
    > >
    > > Reproduced on Conectiva Linux 7.0.
    > > So far:
    > >
    > > mingetty: Not vulnerable
    > > getty: Vulnerable
    > > uugetty: Vulnerable
    > > mgetty: Not vulnerable (only root can execute)
    > >
    > > And there goes a question: is there any reason to someone other than root
    > > have execute permission ? mgetty is 700 here.

    -- 
     Rodrigo Barbosa                   - rodrigob at bh.conectiva.com.br
     Conectiva S/A			   - Belo Horizonte, MG, Brazil
     "Quis custodiet ipsos custodiet?" - http://www.conectiva.com/
    

    -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org

    iD8DBQE8Dj8an5NdOMMM/nERAjNMAKCfecEP5RfpG8dP6/vaH0Gzmlc7SgCgsnX0 DiGoMt4BmSMdZOA0hM4t5Zk= =7H9M -----END PGP SIGNATURE-----