Bugtraq mailing list archives

Re: MDKSA-2000:065 - Linux-Mandrake not affected by dump


From: Fernando Schapachnik <fpscha () NS1 VIA-NET-WORKS NET AR>
Date: Thu, 2 Nov 2000 23:04:50 -0300

En un mensaje anterior, Linux Mandrake Security Team escribió:
                Linux-Mandrake Security Update Advisory
________________________________________________________________________

Package name:         dump
Date:                 November 2nd, 2000
Advisory ID:          MDKSA-2000:065

Affected versions:    None
________________________________________________________________________

Problem Description:

 In some instances, if dump is suid root, it can be used to gain root
 access.  Two exploits have been published to prove this.
________________________________________________________________________

Linux-Mandrake ships dump suid root, however both exploits do not work
under Linux-Mandrake.  The end result is a shell that is suid by the
user attempting the exploit, and not suid root which is the intended
result.

Come on! *These* exploit not working doesn't mean you are not
vulnerable.

Regards.



Fernando P. Schapachnik
Administración de la red
VIA NET.WORKS ARGENTINA S.A.
fschapachnik () vianetworks com ar
Conmutador: (54-11) 4323-3333 - Soporte: 0810-333-AYUDA


Current thread: