Home page logo
/

bugtraq logo Bugtraq mailing list archives

Re: License Manager's lockfiles (Solaris 2.5.1)
From: pedward () WEBCOM COM (pedward () WEBCOM COM)
Date: Fri, 23 Oct 1998 14:56:07 -0700



bash$ ls -l /var/tmp/.flexlm
total 2
-rw-rw-rw-   1 root     root         163 Oct 21 19:55 lmgrd.211

I tested the bug by removing lockESRI and making a symlink to
/var/tmp/test, in about a minute the file was created, owned by root and
worldwrite'able.


Try creating a wrapper shell script that sets the umask before launching
the license manager.  If you set it properly, they won't be world writable
(providing that the LM uses open(filename, O_EXCL | O_CREAT);

This *sounds* like a simple misuse of the open syntax.


/Joel Eriksson


--Perry

--
Perry Harrington        System Software Engineer    zelur xuniL  ()
http://www.webcom.com  perry.harrington () webcom com  Think Blue.  /\



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]