Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: cpio TOCTOU file-permissions vulnerability
From: Steve G <linux_4ever () yahoo com>
Date: Tue, 19 Apr 2005 05:34:55 -0700 (PDT)

Hello,

Since no fix has been posted, I've taken a stab at patching this. I think this
patch solves all issues with chmod & chown. I would recommend people review this
patch and apply since cpio can create suid files, devices, and directories with
special permissions. I have a patch for coreutils mostly done and will post that
soon.

-Steve Grubb


                
__________________________________ 
Do you Yahoo!? 
Make Yahoo! your home page 
http://www.yahoo.com/r/hs

Attachment: cpio-2.6-chmod.patch
Description: cpio-2.6-chmod.patch


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]