Bugtraq mailing list archives
Re: majordomo local exploit
From: cwilson () NEU SGI COM (Chan Wilson)
Date: Fri, 7 Jan 2000 16:27:32 +0100
The following patch, built upon code and suggestions submitted by Henrik Edlund, Henrik Nordstrom, and Andrew Brown, is intended to render safe the config file requires, in the seven scripts which use them, in the Majordomo 1.94.4 home directory. It also incorporates Todd Miller's patch of Dec. 29.
This doesn't address the problem on Unixen that allow one to 'give away' files. Nor is it compatible with the philosophy that majordomo 1.x should continue to run under perl4. The proper fix appears to be simply 'chmod 0750 wrapper', perhaps along with setting the group owner of wrapper to the same as the MTA. And, of course, restricting access to the majordomo server. --Chan majordomo maintainer.
Current thread:
- Re: majordomo local exploit John Archie (Jan 01)
- <Possible follow-ups>
- Re: majordomo local exploit Olaf Kirch (Jan 03)
- Re: majordomo local exploit Dale Clark (Jan 03)
- Re: majordomo local exploit Chan Wilson (Jan 07)