From owner-freebsd-security@FreeBSD.ORG Mon Nov 14 16:48:36 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B22E516A41F for ; Mon, 14 Nov 2005 16:48:36 +0000 (GMT) (envelope-from simon@eddie.nitro.dk) Received: from eddie.nitro.dk (zarniwoop.nitro.dk [83.92.207.38]) by mx1.FreeBSD.org (Postfix) with ESMTP id 45C0143D45 for ; Mon, 14 Nov 2005 16:48:36 +0000 (GMT) (envelope-from simon@eddie.nitro.dk) Received: by eddie.nitro.dk (Postfix, from userid 1000) id C0929119C50; Mon, 14 Nov 2005 17:48:34 +0100 (CET) Date: Mon, 14 Nov 2005 17:48:34 +0100 From: "Simon L. Nielsen" To: Dmitry Grigorovich Message-ID: <20051114164833.GG64196@eddie.nitro.dk> References: <000b01c5e934$4ed79690$160219ac@bionet.nsc.ru> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="QWpDgw58+k1mSFBj" Content-Disposition: inline In-Reply-To: <000b01c5e934$4ed79690$160219ac@bionet.nsc.ru> User-Agent: Mutt/1.5.11 Cc: freebsd-security@freebsd.org Subject: Re: Race condition in Sudo's pathname validation, version <= 1.6.8p9 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 14 Nov 2005 16:48:36 -0000 --QWpDgw58+k1mSFBj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2005.11.14 21:58:49 +0600, Dmitry Grigorovich wrote: > http://sudo.ws/sudo/alerts/path_race.html See http://vuxml.FreeBSD.org/3bf157fa-e1c6-11d9-b875-0001020eed82.html for details regarding this vulnerability in the context of the FreeBSD Ports Collection. Note that this is a rather old issue which was published 2005-06-20. --=20 Simon L. Nielsen FreeBSD Security Team --QWpDgw58+k1mSFBj Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFDeL/hh9pcDSc1mlERArZBAJ90krnKK2rcMEFa9jwQf/73omaVMQCcCwWf BFFD7e6/aetyXC45f+SpOCg= =I7A1 -----END PGP SIGNATURE----- --QWpDgw58+k1mSFBj--