Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Repost: Security bug in SGI VideoFramer

Re: Repost: Security bug in SGI VideoFramer

From: <martinh_at_mailhost.emap.co.uk>
Date: Thu, 23 May 1996 10:03:01 +0000

On Tue, 14 May 1996, Hui-Hui Hu wrote:

> Stardot Networks / Security vulnerability [SDN-2-sgi-videoframer]
>
> PROBLEM. sb_encode is installed setuid in /usr/video/vfr/bin and does not
> check for permissions/ownership. sb_encode takes an IRIS RGB-format image
> file and spits out a VideoFramer format file (.vfr).
>
> REPEAT BY: /usr/video/vfr/bin/sb_encode -o [file-to-overwrite] [iris-image]
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

> TEMPORARY FIX.
>
> # chmod -s /usr/video/vfr/*

Since the sb_encode program is in a subdirectory of /usr/video/vfr/
shouldn't the fix be:

# chmod -R -s /usr/video/vfr/*

M.

##################################################################
# Martin Hargreaves (martin_at_datamodl.demon.co.uk) Computational #
# Director, Datamodel Ltd Chemist #
# Contract Unix system admin/Unix security Sysadmin #
##################################################################
Received on May 23 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos