Bugtraq mailing list archives

Re: format bug in agetty ??


From: Gordon Messmer <yinyang () EBURG COM>
Date: Wed, 20 Sep 2000 18:43:26 -0700

On Tue, 19 Sep 2000, Carlos Eduardo Gorges wrote:

#define debug(s) fprintf(dbf,s); fflush(dbf)
...
                        debug(argv[i]);

Yeah, that's definitely a problem.  However, it's probably only
exploitable if agetty is installed SUID, which it shouldn't be.


Current thread: