Bugtraq mailing list archives
Re: MDKSA-2000:065 - Linux-Mandrake not affected by dump
From: Fernando Schapachnik <fpscha () NS1 VIA-NET-WORKS NET AR>
Date: Thu, 2 Nov 2000 23:04:50 -0300
En un mensaje anterior, Linux Mandrake Security Team escribió:
Linux-Mandrake Security Update Advisory ________________________________________________________________________ Package name: dump Date: November 2nd, 2000 Advisory ID: MDKSA-2000:065 Affected versions: None ________________________________________________________________________ Problem Description: In some instances, if dump is suid root, it can be used to gain root access. Two exploits have been published to prove this. ________________________________________________________________________ Linux-Mandrake ships dump suid root, however both exploits do not work under Linux-Mandrake. The end result is a shell that is suid by the user attempting the exploit, and not suid root which is the intended result.
Come on! *These* exploit not working doesn't mean you are not vulnerable. Regards. Fernando P. Schapachnik Administración de la red VIA NET.WORKS ARGENTINA S.A. fschapachnik () vianetworks com ar Conmutador: (54-11) 4323-3333 - Soporte: 0810-333-AYUDA
Current thread:
- MDKSA-2000:065 - Linux-Mandrake not affected by dump Linux Mandrake Security Team (Nov 03)
- Re: MDKSA-2000:065 - Linux-Mandrake not affected by dump Adam Knight (Nov 04)
- Re: MDKSA-2000:065 - Linux-Mandrake not affected by dump Fernando Schapachnik (Nov 05)