|
Bugtraq
mailing list archives
Re: MDKSA-2000:065 - Linux-Mandrake not affected by dump
From: Fernando Schapachnik <fpscha () NS1 VIA-NET-WORKS NET AR>
Date: Thu, 2 Nov 2000 23:04:50 -0300
En un mensaje anterior, Linux Mandrake Security Team escribió:
Linux-Mandrake Security Update Advisory
________________________________________________________________________
Package name: dump
Date: November 2nd, 2000
Advisory ID: MDKSA-2000:065
Affected versions: None
________________________________________________________________________
Problem Description:
In some instances, if dump is suid root, it can be used to gain root
access. Two exploits have been published to prove this.
________________________________________________________________________
Linux-Mandrake ships dump suid root, however both exploits do not work
under Linux-Mandrake. The end result is a shell that is suid by the
user attempting the exploit, and not suid root which is the intended
result.
Come on! *These* exploit not working doesn't mean you are not
vulnerable.
Regards.
Fernando P. Schapachnik
Administración de la red
VIA NET.WORKS ARGENTINA S.A.
fschapachnik () vianetworks com ar
Conmutador: (54-11) 4323-3333 - Soporte: 0810-333-AYUDA
By Date
By Thread
Current thread:
|