Bugtraq mailing list archives

FreeBSD and suidperl


From: Kris Kennaway <kris () FREEBSD ORG>
Date: Thu, 10 Aug 2000 14:43:17 -0700

Just wanted to confirm for the audience that no versions of FreeBSD are
vulnerable to the suidperl exploit because of the hardcoded /bin/mail path
which does not exist on FreeBSD (all 4.4BSD-derived systems?).

We won't be releasing an advisory, because I think releasing an advisory
saying nothing but "Attention! Attention! This program is not insecure!
Carry on." is silly :-)

Kris

--
In God we Trust -- all others must submit an X.509 certificate.
    -- Charles Forsythe <forsythe () alum mit edu>


Current thread: