Date: Sat, 8 Nov 1997 01:26:02 +0100 From: Ollivier Robert <roberto@keltia.freenix.fr> To: security@FreeBSD.ORG Subject: Re: Fwd: "possible freebsd su problem?" <taz@primenet.com> Message-ID: <19971108012602.14691@keltia.freenix.fr> In-Reply-To: <19971107095506.35947@deepo.prosa.dk>; from Philippe Regnauld on Fri, Nov 07, 1997 at 09:55:06AM %2B0100 References: <19971107095506.35947@deepo.prosa.dk>
next in thread | previous in thread | raw e-mail | index | archive | help
According to Philippe Regnauld: > Is there any potential concern for this ? > > -----Forwarded message from taz <taz@primenet.com>----- > > Date: Thu, 6 Nov 1997 11:30:02 -0600 > From: taz <taz@primenet.com> > Subject: possible freebsd su problem? > To: BUGTRAQ@NETSPACE.ORG > > I checked the archives, not a word of this was to be found so here > goes. > > First off, my o/s: > FreeBSD xxxxxx 2.2.1-RELEASE > > Upon running su today, which is obviously setuid on most systems, > I used the argument '--' instead of '-'. This caused it to seg fault. I > ran gdb on it and found the problem was in a getpwnam() call. here is the > source. Fixed a while ago: joerg 1997/08/23 07:09:37 PDT Modified files: usr.bin/su su.c Log: Prevent a NULL dereferencation when given a garbage command line. PR: bin/3206 Submitted by: blank@fox.uni-trier.de -- Ollivier ROBERT -=- FreeBSD: The Power to Serve! -=- roberto@keltia.freenix.fr FreeBSD keltia.freenix.fr 3.0-CURRENT #46: Sun Nov 2 16:51:01 CET 1997
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19971108012602.14691>