Lotus Notes security hole

From: Magosanyi Arpad (magat_private)
Date: Fri Mar 20 1998 - 07:11:00 PST

  • Next message: Peter van Dijk: "/tmp race in Linux kernel source!"

    Hi!
    
    Sorry if it is already reported.
    
    I have a Lotus Notes 4.5 (Intl) on a SunOS 5.5.1 Generic sun4m sparc
    SUNW,SPARCstation-10.
    
    The Notes client talks through shared memory with its various parts.
    
    IPC status from <running system> as of Fri Mar 20 16:07:47 1998
    T     ID     KEY        MODE       OWNER    GROUP
    Message Queues:
    Shared Memory:
    m  26113 0xf8000000 --rw-rw----      mag      usr
    m  26114 0xf8000001 --rw-rw----      mag      usr
    m  26115 0xf8000002 --rw-rw----      mag      usr
    m  18948 0xf8000003 --rw-rw----      mag      usr
    
    That means that anyone in my primary group can read and write those shmem
    segments. I hope it is not directly equivalent with mailbox being mode 660,
    but one never can be sure enough.
    Can someone shed some light on it?
    
    A workaround i can think of: make a private primary group for each user. It
    is recommended anyway.
    
    --
    GNU GPL: csak tiszta forrásból
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:46:20 PDT