Bugtraq mailing list archives

Re: Solaris /usr/bin/mailx exploit (SPARC)


From: Casper Dik <Casper.Dik () Sun COM>
Date: Mon, 14 May 2001 10:24:10 +0200



I'm not sure why all of the Solaris mail programs are actually set-gid 
mail.

If you strip set-gid mail from /usr/bin/mail,, /usr/bin/mailx, 
/usr/SUNWale/bin/mailx, /usr/dt/bin/dtmail, /usr/dt/bin/dtmailpr,
/usr/openwin/bin/mailtool nothing should break.

(At least not if you /var/mail directory has the standard 1777 permissions)


By forcing a file permission of 600 on mailboxes, group mail should not
gain you anything.

Casper


Current thread: