Home page logo

bugtraq logo Bugtraq mailing list archives

Re: Solaris /usr/lib/exrecover buffer overflow
From: Darren J Moffat <Darren.Moffat () ENG SUN COM>
Date: Tue, 9 Jan 2001 15:41:38 -0800

Pablo Sor wrote:

The /usr/lib/exrecover contains a buffer overflow
(this command is suid in Solaris 2.4/5/6)

Starting with Solaris 7 exrecover is no longer installed setuid root.

It is safe to change the exrecover permissions to 0555 on all other
releases since it doesn't need elevated privleges to do its job;
/var/preserve is 1777.

This is Sun bug# 4161925

Darren J Moffat

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]