Bugtraq mailing list archives
Re: Troff dangerous.
From: okir () MONAD SWB DE (Olaf Kirch)
Date: Mon, 26 Jul 1999 11:20:23 +0200
On Sun, 25 Jul 1999 10:18:20 EDT, John Robert LoVerso wrote:
This isn't a problem with "troff" or any of it's varients. Instead, this is an exploit purely with "groff", the GNU reimplementation. Troff doesn't have the file stream or ".pso" requests; those are purely part of groff.
No, at least .sy and .pi are part of the original troff command set. Look for the original troff documentation in the att cstr series. As far as man viewers are concerned, these problems have been discovered and fixed several times. On Linux, Andries Brouwer's man is safe; it drops privileges whenever it invokes external commands (note that this includes gzip and less besides groff). The man_db shipped by some vendors isn't. I've repeately tried to contact the original author, to no avail. Potential problems like this are also the primary reason why /usr/man and friends should never be owned by man.man; once you've subverted user or group man you may be able to plant trojan manpages in them. Finally, note that apart from the various troff/groff commands, you can request that certain preprocessors like tbl be run. Some of them also have special commands that make them run shell code. Olaf -- Olaf Kirch | --- o --- Nous sommes du soleil we love when we play okir () monad swb de | / | \ sol.dhoop.naytheet.ah kin.ir.samse.qurax
Current thread:
- Re: Troff dangerous. John Robert LoVerso (Jul 25)
- Re: Troff dangerous. Nic Bellamy (Jul 25)
- Re: Troff dangerous. Aaron Campbell (Jul 26)
- Re: Troff dangerous. Olaf Kirch (Jul 26)
- <Possible follow-ups>
- Re: Troff dangerous. Joel Eriksson (Jul 25)
- Re: Troff dangerous. Pete (Jul 25)
- Re: Troff dangerous. Robert Watson (Jul 27)
- Re: Troff dangerous. Yozo Toda (Jul 25)
- Re: Troff dangerous. Eric Moore (Jul 25)
- Re: Troff dangerous. Ville Nummela (Jul 27)
- Re: Troff dangerous. Pete (Jul 25)
- Re: Troff dangerous. Jason Thorpe (Jul 25)
- Retrieving RDS Data... Wanderley J. Abreu Jr (Jul 26)
- Re: Troff dangerous. Bob Beck (Jul 26)
- Re: Troff dangerous. Ronny Cook (Jul 25)
(Thread continues...)
- Re: Troff dangerous. Nic Bellamy (Jul 25)
