Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 8 Nov 1997 01:26:02 +0100
From:      Ollivier Robert <roberto@keltia.freenix.fr>
To:        security@FreeBSD.ORG
Subject:   Re: Fwd: "possible freebsd su problem?" <taz@primenet.com>
Message-ID:  <19971108012602.14691@keltia.freenix.fr>
In-Reply-To: <19971107095506.35947@deepo.prosa.dk>; from Philippe Regnauld on Fri, Nov 07, 1997 at 09:55:06AM %2B0100
References:  <19971107095506.35947@deepo.prosa.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
According to Philippe Regnauld:
> 	Is there any potential concern for this ?
> 
> -----Forwarded message from taz <taz@primenet.com>-----
> 
> Date:         Thu, 6 Nov 1997 11:30:02 -0600
> From: taz <taz@primenet.com>
> Subject:      possible freebsd su problem?
> To: BUGTRAQ@NETSPACE.ORG
> 
>         I checked the archives, not a word of this was to be found so here
> goes.
> 
> First off, my o/s:
> FreeBSD xxxxxx 2.2.1-RELEASE
> 
>         Upon running su today, which is obviously setuid on most systems,
> I used the argument '--' instead of '-'. This caused it to seg fault. I
> ran gdb on it and found the problem was in a getpwnam() call. here is the
> source.

Fixed a while ago:

joerg       1997/08/23 07:09:37 PDT

  Modified files:
    usr.bin/su           su.c 
  Log:
  Prevent a NULL dereferencation when given a garbage command line.
  
  PR:           bin/3206
  Submitted by: blank@fox.uni-trier.de

-- 
Ollivier ROBERT -=- FreeBSD: The Power to Serve! -=- roberto@keltia.freenix.fr
FreeBSD keltia.freenix.fr 3.0-CURRENT #46: Sun Nov  2 16:51:01 CET 1997



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19971108012602.14691>