Bugtraq mailing list archives
Re: IRIX: Bug in startmidi
From: sma () NAS NASA GOV (Steve M. Acheson)
Date: Mon, 10 Feb 1997 09:18:56 -0800
Whilst browsing around the filesystem on my SGI (running IRIX 5.3), I noticed a little suid-root program called 'startmidi' which hides in /usr/sbin. When run, this program creates various files in /tmp. You guessed it, it respects umask and follows symlinks. Comme ca:
[ example ...]
eh... that's strange. I was looking at startmidi a while back, but didn't find any root holes. Now I look again, still nothing. Indeed, on my 5.3umm..I can successfully create file owned by root..You must have some special configuration, I recon. On the box I was testingI don't think it's special to his machine, I've got the same behaviour as described (though stopmidi can't remove the file already in /tmp).
All of my systems, 5.3/6.2/6.3 are immune to this problem. We also have all of the security patches installed. Something I did notice, is that when it creates the socket in /tmp/midififo, it properly deals with user perms, and doens't follow symlinks, but it doesn't reset the group of the fifo. It left it as my primary group. While the permissons of it are 600 it isn't a big concern, but it probably would be better as group root. Just my paranoia... Satch -- ================================================================ Steve Acheson sma () nas nasa gov Numerical Aerospace Simulation Facility 415-604-4495 NASA Ames - MS 258-6 Moffett Field, Ca 94035-1000
Current thread:
- Re: FreeBSD,rlogin and coredumps., (continued)
- Re: FreeBSD,rlogin and coredumps. Adrian Chadd (Feb 17)
- Re: FreeBSD,rlogin and coredumps. Jamshid Abedi (Feb 17)
- Re: FreeBSD,rlogin and coredumps. jamie (Feb 18)
- Re: FreeBSD,rlogin and coredumps. Nathan Torkington (Feb 18)
- Re: FreeBSD,rlogin and coredumps. Daniel O'Callaghan (Feb 18)
- Re: FreeBSD,rlogin and coredumps. Simon Karpen (Feb 18)
- Re: FreeBSD,rlogin and coredumps. Michael Lerperger (Feb 17)
- NetBIOS Auditing Tool Oliver Friedrichs (Feb 16)
- Re: IRIX: Bug in startmidi Astley Chan (Feb 09)
- Re: IRIX: Bug in startmidi Steve M. Acheson (Feb 10)