Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Amanda multiple vendor local root compromises
From: oliva () LSD IC UNICAMP BR (Alexandre Oliva)
Date: Tue, 2 Nov 1999 09:41:13 -0200


On Nov  1, 1999, monti <monti () USHOST COM> wrote:

I confirmed a few exploitable buffer overflows in multiple suid's on an
earlier version of amanda on BSDI as well a while back. As I recollect
'runtar' was one of them.

It's probably time to refresh your view :-)

Amanda has undergone a major security auditing before release 2.4.0
final (the latest stable release is 2.4.1p1), in which a couple of
security problems have been fixed, and a lot of security problem-prone
constructs have been reworked to avoid buffer overflows and such.

Anyway, we'd be very interested in being informed (preferably in
advance:-) if any problems remained, or if any new ones have been
introduced.

Thanks for your concern.

--
Alexandre Oliva http://www.ic.unicamp.br/~oliva IC-Unicamp, Bra[sz]il
oliva () {lsd ic unicamp br,guarana.{org,com}} aoliva () {acm,computer}.org
oliva () {gnu org,kaffe.org,{egcs,sourceware}.cygnus.com,samba.org}
** I may forward mail about projects to mailing lists; please use them



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]