Bugtraq mailing list archives

Re: Redhat 6.2 dump command executes external program with suid priviledge


From: Christopher McCrory <chrismcc () PRICEGRABBER COM>
Date: Wed, 1 Nov 2000 08:05:41 -0800

Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hello...

This is the location for the latest version
ftp://ftp.sourceforge.net/pub/sourceforge/dump/

dump is no longer suid root.
        
I tested the short exploit on RedHat7 (dump-0.4b19-4) and was _not_
successful. Redhat7 does not ship dump suid root.  I tested the exploit
on the latest version from sourceforge (dump-0.4b19-1) was was _not_
successful.  An untested workaround would probably be to remove the suid
bit from /sbin/dump, but I haven't verified it as all my servers was
already running 0.4b19.




--

Christopher McCrory
"The guy that keeps the servers running"
chrismcc () pricegrabber com
http://www.pricegrabber.com

"Linux: Because rebooting is for adding new hardware"


Current thread: