Home page logo

bugtraq logo Bugtraq mailing list archives

Re: GNU/Linux 'info Buffer Overflow
From: "Janusz A. Urbanowicz" <alex () syjon fantastyka net>
Date: Sat, 7 Aug 2004 17:31:11 +0200

On Fri, Aug 06, 2004 at 11:41:12PM +0200, Niels Bakker wrote:
/usr/bin/info is not setuid, and I can't think of any way to invoke the
program where it would allow for privilege escalation.  Why is the
severity "grave?" Remember that this is bugtraq, about security, not
the Debian bug tracking system, or texinfo's gnats.

I think that the severity is overstated for Debian BTS too, IMO - and
according to Debian Policy - this should be 'normal' or 'serious' at


PS> Niels, your advertised address bounces with virtusertable errors,
I tried to send this offlist first.

Attachment: _bin

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]