Date: Sat, 8 Nov 1997 01:26:02 +0100 From: Ollivier Robert <roberto@keltia.freenix.fr> To: security@FreeBSD.ORG Subject: Re: Fwd: "possible freebsd su problem?" <taz@primenet.com> Message-ID: <19971108012602.14691@keltia.freenix.fr> In-Reply-To: <19971107095506.35947@deepo.prosa.dk>; from Philippe Regnauld on Fri, Nov 07, 1997 at 09:55:06AM %2B0100 References: <19971107095506.35947@deepo.prosa.dk>
index | next in thread | previous in thread | raw e-mail
According to Philippe Regnauld:
> Is there any potential concern for this ?
>
> -----Forwarded message from taz <taz@primenet.com>-----
>
> Date: Thu, 6 Nov 1997 11:30:02 -0600
> From: taz <taz@primenet.com>
> Subject: possible freebsd su problem?
> To: BUGTRAQ@NETSPACE.ORG
>
> I checked the archives, not a word of this was to be found so here
> goes.
>
> First off, my o/s:
> FreeBSD xxxxxx 2.2.1-RELEASE
>
> Upon running su today, which is obviously setuid on most systems,
> I used the argument '--' instead of '-'. This caused it to seg fault. I
> ran gdb on it and found the problem was in a getpwnam() call. here is the
> source.
Fixed a while ago:
joerg 1997/08/23 07:09:37 PDT
Modified files:
usr.bin/su su.c
Log:
Prevent a NULL dereferencation when given a garbage command line.
PR: bin/3206
Submitted by: blank@fox.uni-trier.de
--
Ollivier ROBERT -=- FreeBSD: The Power to Serve! -=- roberto@keltia.freenix.fr
FreeBSD keltia.freenix.fr 3.0-CURRENT #46: Sun Nov 2 16:51:01 CET 1997
help
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19971108012602.14691>
