Bugtraq mailing list archives

Re: majordomo local exploit


From: huuskone () CC HELSINKI FI (Taneli Huuskonen)
Date: Wed, 29 Dec 1999 17:30:15 +0200


-----BEGIN PGP SIGNED MESSAGE-----

"Todd C. Miller" <Todd.Miller () COURTESAN COM> wrote:

For those using perl 5.x, you can use sysopen() instead of the "magic"
perl open() to fix this.

I'm afraid that wouldn't help much, as you can supply any pathname as
the -C (configuration file) argument:

        /path/to/majordomo/wrapper resend -l foobar -C /tmp/evilhack.pl

I tested this with version 1.94.1, but the same behaviour seems to be
there in 1.94.4, as far as I can tell by the source.

Taneli Huuskonen

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQB1AwUBOGoorAUw3ir1nvhZAQF31gL9HRxD8LOVsilgTuj5iRRTHdhI0cGS7AF/
cBzVkofDCcu4UamxZj7weOqK//EbHPjEuFE7ABW4sb4CHXigA0rVuc/B2QKntX7A
UmceOIjDSU8iVj5FqFkbo9u3uysC8ngl
=Iy7+
-----END PGP SIGNATURE-----

--
I don't   | All messages will be PGP signed,  | Fight for your right to
speak for | encrypted mail preferred.  Keys:  | use sealed envelopes.
the Uni.  | http://www.helsinki.fi/~huuskone/ | http://www.gilc.org/



Current thread: