Bugtraq mailing list archives

Re: [ Hackerslab bug_paper ] HP-UX crontab temporary file symboliclink vulnerability


From: Kris Kennaway <kris () CITUSC17 USC EDU>
Date: Wed, 25 Oct 2000 14:58:53 -0700

On Wed, Oct 25, 2000 at 12:30:47PM +0200, Fabio Pietrosanti (naif) wrote:
Tested also on:

FreeBSD 3.3 = Vulnerable
FreeBSD 2.2.8 = Vulnerable

Are you sure? Our testing indicates that you can't read an arbitrary
file, it must conform to cron syntax - basically meaning either all
lines commented out with a #, or an actual cron job file.

I don't have access to a 2.x machine to test (and in fact the 2.2.x
series has not been officially supported for some time), but I believe
3.5-RELEASE has the above properties I describe.

Kris


Current thread: