Vulnerability Development mailing list archives

Re: Local root through vulnerability in ping on linux.


From: Matt Wilson <msw () REDHAT COM>
Date: Wed, 23 Aug 2000 02:02:20 -0400

Fixed with this patch...

Matt

On Tue, Aug 22, 2000 at 03:57:03PM +0200, Michal Zalewski wrote:
On Tue, 22 Aug 2000, Bluefish (P.Magnusson) wrote:

Doesn't seem exploitable, but a bit funny :)

To keep it short, no coredump so far, neither as root or user, no matter
packet size while doing /usr/sbin/traceroute -g 127.0.0.1 127.0.0.1

Try with other IPs that will expand to different DNS entries. Also, try
replacing one of these IPs with DNS name and so on.

Every time, effect will be different ;P

Attachment: traceroute-1.4a5-sourceroute.patch
Description:


Current thread: