Bugtraq mailing list archives

Re: pmpost - another nice symlink follower


From: Lynton Clamp <lynton () nobarrier co za>
Date: Tue, 19 Jun 2001 11:08:06 +0200

Found the same on one of our SuSE 7.1 workstations and can confirm that it
works on that as well.

Regards,

Lynton


On 2001.06.18 19:11:20 +0200 Paul Starzetz wrote:
Hi,

there is a symlink handling problem in the pcp suite from SGI. The
binary pmpost will follow symlinks, if setuid root this leads to instant
root compromise, as found on SuSE 7.1 (I doubt that this a default SuSE
package, though).



Current thread: