Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 13 Apr 2002 10:06:29 -0700 (PDT)
From:      Mikko Tyolajarvi <mikko@dynas.se>
To:        cmr@iisc.com
Cc:        security@freebsd.org
Subject:   Re: [Corrected message] This OpenBSD local root hole may affect some FreeBSD systems 
Message-ID:  <200204131706.g3DH6T117776@mikko.rsa.com>
References:  Your message of "Thu, 11 Apr 2002 23:58:03 MDT."              <4.3.2.7.2.20020411235129.00ba5bc0@nospam.lariat.org>  <200204121134.HAA23582@koibito.iisc.com>

next in thread | previous in thread | raw e-mail | index | archive | help
In local.freebsd.security you write:


>Up-to-date patched Solaris 8:

>amaterasu $ pwd
>/export/home/cmr
>amaterasu $ echo "~\!touch foo" | mail cmr
>amaterasu $ ls -l foo
>foo: No such file or directory
>amaterasu $ ls -l /usr/bin/mail
>-r-x--s--x   1 root     mail       61080 Mar  6 18:01 /usr/bin/mail

>Up-to-date patched Solaris 7

>taiyou $ pwd
>/export/home/cmr
>taiyou $ echo "~\!touch foo" | mail cmr
>taiyou $ ls -l foo
>foo: No such file or directory
>taiyou $ ls -l /usr/bin/mail
>-r-x--s--x   1 bin      mail       66796 Mar  1 18:14 /usr/bin/mail

Try "mailx" or /usr/ucb/mail...

   $.02,
   /Mikko
-- 
 Mikko Työläjärvi_______________________________________mikko@rsasecurity.com
 RSA Security

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200204131706.g3DH6T117776>