Bugtraq mailing list archives

Re: BUGTRAQ ALERT: Solaris 2.x vulnerability


From: nlawson () statler csc calpoly edu (Nathan Lawson)
Date: Wed, 16 Aug 1995 01:42:36 -0700


Aleph1 said:
Well while we taling about SysV ps IRIX's its sgid to sys, writes
to /tmp/.ps_data and /tmp/.ps_XXXXXX but /tmp was the sticky bit on.

The /tmp/.psXXXXXX is open to a race.  The directory is safe as long as it
isn't world writable.

-Nate



Current thread: