Bugtraq mailing list archives

Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow


From: avalon () COOMBS ANU EDU AU (Darren Reed)
Date: Fri, 7 Jan 2000 10:06:31 +1100


In some mail from "±è¿ëÁØ KimYongJun (99Á¹¾÷)", sie said:

[Hackerslab bug_paper] Solaris chkperm buffer overflow


File   :   /usr/vmsys/bin/chkperm

SYSTEM :   Solaris 2.x

How amusing.

On of my Solaris7 box's (incidently was pre-installed by Sun) doesn't
appear to have SUNWfac installed.  Those that I did myself (complete
OS install) do.

Seems you might be able to do a "pkgrm SUNWfac" and just delete it unless
you actually make use of it.

% grep chkperm /var/sadm/install/contents
/usr/vmsys/bin/chkperm f none 6755 bin bin 10080 40420 904647701 SUNWfac
% pkginfo SUNWfac
system      SUNWfac        Framed Access Command Environment

Darren


Current thread: