Bugtraq mailing list archives

BSD mail.local has race condition


From: travis () EvTech com (Travis Hassloch x231)
Date: Wed, 10 Jul 1996 14:17:16 -0500


Same as the Solaris mailx bug.  As usual, to exploit the bug, you
have to have write perms to the mail spool.  This means a security
conscious admin should turn world-write off, but this may break
mail user agents.  A mail.local fix should be forthcoming, but
is pretty obvious -- same deal as writing to /tmp or other world-write
dirs from an SUID root program.

I had a stupid response to the Solaris mailx bug; I hope it didn't
get propogated here (it went out to Best-Of, oops).  Sorry, I was
going cold-turkey on the caffeine, and was judgement-challenged.
--
Travis Hassloch, Electronic Blacksmith | P=NP if (P=0 or N=1)
There's a fine line between an email message and its signature.



Current thread: