Bugtraq mailing list archives

Re: smbd remote file creation vulnerability


From: Wichert Akkerman <wichert () wiggy net>
Date: Wed, 27 Jun 2001 00:42:52 +0200

Previously Pavol Luptak wrote:
Linux kernels with openwall patch (with restricted links in /tmp) are
imunne to this type of attack (following symlinks does not work, link
owner does not match with file's owner).

If symlink don't work you can still use a hardlink though.

Wichert.

-- 
  _________________________________________________________________
 /       Nothing is fool-proof to a sufficiently talented fool     \
| wichert () cistron nl                  http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |


Current thread: