Bugtraq mailing list archives

system() call in suid programs


From: czetts () rpi edu (Not Joe)
Date: Fri, 14 Jun 1996 10:18:35 +22304652


Hello,

I know that it is bad to use the system() system call in programs, especially
ones that are suid root, and that it can be exploited fairly easily.  Could
somebody post or send me details how exploits based on the system() call work?
Detail would be good, as I am supposed to explain the security implications
to my boss at our next meeting.

Thanks in advance.

-Steve



Current thread: