Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 4 Jul 1996 09:50:02 +0200 (MET DST)
From:      guido@gvr.win.tue.nl (Guido van Rooij)
To:        danp@carebase3.jri.org (Dan Polivy)
Cc:        freebsd-security@freebsd.org
Subject:   Re: is FreeBSD's rdist vulnerable?
Message-ID:  <199607040750.JAA14410@gvr.win.tue.nl>
In-Reply-To: <Pine.BSF.3.91.960703191714.1090A-100000@carebase3.jri.org> from Dan Polivy at "Jul 3, 96 07:21:07 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
Dan Polivy wrote:
> Hey,
> 
> Has anyone read 8lgm's rdist advisory and attempted to see whether or not 
> FreeBSD's rdist is vulnerable?  I use rdist to update various files here, 
> and so I suppose getting id of the setuid bit would break it?  Thanks...

Yes it is vulnerable.

-Guido



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199607040750.JAA14410>