Full Disclosure mailing list archives
HP-UX 11.0 /usr/lbin/rwrite
From: bt () delfi lt
Date: Fri, 2 May 2003 20:16:53 +0300
Hi! There is a vulnerability in /usr/lbin/rwrite on HP-UX 11.0 (other versions might be vulnerable too). /usr/lbin/rwrite is installed setuid to root by default. $ /usr/lbin/rwrite something `perl -e 'print "A" x 14628'` something Segmentation fault Solution : remove setuid bit until patch is available. Tried to contact security-alert () hp com , got "Client rejected. Access denied". Bye, bt () delfi lt <--------------------===========================--------------------> Meiles zinutes sirdies damai ar riteriui: siusk MEILE numeriu 1325. Jei siunti draugui, po zodzio MEILE nurodyk jo mob. telefono numeri. Zinutes kaina 1 Lt. http://sms.delfi.lt/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- HP-UX 11.0 /usr/lbin/rwrite bt (May 02)
- Re: HP-UX 11.0 /usr/lbin/rwrite KF (May 02)