Bugtraq mailing list archives

Re: BUGTRAQ ALERT: Solaris 2.x vulnerability


From: rukshin () caip rutgers edu (David Rukshin)
Date: Fri, 18 Aug 1995 08:42:54 BST


: Just to add my two cents to the discussion:
:        - it is fixed in 2.5 (by using fchown, not chown, both versions of ps)

I was able to reproduce the problem on a SPARC 5/85 running Solaris 2.5 BETA
within approximately 2.5 minutes when using /usr/bin/ps
I was not very successful in doing so with /usr/ucb/ps.  But then again, may
be I haven't let the job run long enough.

Dave

__________________________________________________________________________
David Rukshin                                   <rukshin () caip rutgers edu>
Student Systems Programmer                      {...}!rutgers!caip!rukshin
CAIP Center, Rutgers University                 614 CoRE Blng 908/445-5553



Current thread: