Bugtraq mailing list archives

Re: vulnerability in vi under AIX 3.2


From: wfp5p () tigger itc virginia edu (Bill Pemberton)
Date: Tue, 23 Jul 1996 13:38:07 -0400



Hello all. I have found out that under AIX 3.2 the vi editor interprets
the file ./.exrc, even if you are root and this file is not owned by you.
This vulnerability seems rather obvious to me, do you know if a patch
exists for this?


I can not duplicate this on our AIX 3.2.5 machines -- vi only reads
$HOME/.exrc .  Since root's $HOME is /, you've got a bigger problem if folks
can write to the .exrc.....

You can also make sure you run tvi since it will ONLY read /etc/.exrc

--
Bill Pemberton                           wfp5p () virginia edu
ITC/Unix Systems                         flash () virginia edu
University of Virginia                   uunet!virginia!wfp5p



Current thread: