Bugtraq mailing list archives

Re: [HERT] Advisory #002 Buffer overflow in lsof


From: alan () LXORGUK UKUU ORG UK (Alan Cox)
Date: Sat, 20 Feb 1999 01:35:22 +0000


In a few mins I noticed all linux versions are chown .kmem; chmod g+s
lsof...  on linux /dev/kmem is +w for gid kmem, on bsd too (probably, I
didn't checked that), so... all of std. distributions are vuln. without

crw-r-----   1 root     kmem       1,   2 May  5  1998 /dev/kmem

Red Hat 5.2

crw-r-----   1 root     kmem       1,   2 Jan  1  1980 /dev/kmem

Red Hat 4.2

Alan



Current thread: