Bugtraq mailing list archives
vulnerability in vi under AIX 3.2
From: buitrago () cica es (Marina Buitrago Bravo)
Date: Tue, 23 Jul 1996 09:53:49 +0000
Hello all. I have found out that under AIX 3.2 the vi editor interprets the file ./.exrc, even if you are root and this file is not owned by you. This vulnerability seems rather obvious to me, do you know if a patch exists for this? SunOS 4.1.3 has a similar feature, but the file is interpreted only if root owns the file ./.exrc. Thanks in advance, Marina. -- -------------------------------------------------------------------- Marina Buitrago Bravo (buitrago () cica es) Centro Informatico Cientifico de Andalucia (CICA) - Area de Sistemas Avda. Reina Mercedes s/n Tfno: 34 5 4623811 41012 Sevilla Fax: 34 5 4624506 --------------------------------------------------------------------
Current thread:
- Re: HP/UX 10.01 Remote Administration accoun Jeff Uphoff (Jul 18)
- Re: HP/UX 10.01 Remote Administration accoun Mark Sedlock (Jul 18)
- FreeBSD recent exploits. Andy Dills (Jul 18)
- tcp Bj|rge Eikenes (Jul 23)
- Re: tcp Brian Mitchell (Jul 23)
- dg/ux vulnerbility Brian Mitchell (Jul 23)
- vulnerability in vi under AIX 3.2 Marina Buitrago Bravo (Jul 23)
- Re: vulnerability in vi under AIX 3.2 Bill Pemberton (Jul 23)
- Re: vulnerability in vi under AIX 3.2 (IN LINUX) Nelson N. Escravana (Jul 24)
- FreeBSD recent exploits. Andy Dills (Jul 18)
- Re: FreeBSD recent exploits. Cy Schubert - ITSD Open Systems Group (Jul 23)
- Re: HP/UX 10.01 Remote Administration accoun Mark Sedlock (Jul 18)