mailing list archives
Major security-hole in kerberos rsh, rcp and rlogin.
From: e96_agr () E KTH SE (Artur Grabowski)
Date: Mon, 3 Nov 1997 02:18:49 +0100
There has been discovered a security-hole in kerberized rsh, rcp and rlogin.
Everyone who has setuid-bits set on these applications is adviced to disable
The hole allows any user on the system to gain privilegies of any other user
The hole has been successfully tested on kth-kerberos, but is suspected to
exist on any other versions of kerberos.
//Artur Grabowski (administrator on stacken.kth.se)