Re: bug in su (Slackware 3.4)

From: Martin Schulze (joeyat_private)
Date: Sun Mar 22 1998 - 10:49:40 PST

  • Next message: Miquel van Smoorenburg: "Re: An exploit for linux mh ver 6.8.4-5 ( update ) ..."

    --xgI/oilGqZ+PHCdU
    Content-Type: text/plain; charset=us-ascii
    
    Here is a fix for this problem:
    
    --- shadow-970616.orig/libmisc/sulog.c  Sun Mar 22 19:37:00 1998
    +++ shadow-970616/libmisc/sulog.c       Sun Mar 22 19:36:44 1998
    @@ -59,6 +59,7 @@
            if ( (sulog=getdef_str("SULOG_FILE")) == (char *) 0 )
                    return;
    
    +       umask(022);
            if ((fp = fopen (sulog, "a+")) == (FILE *) 0)
                    return;                 /* can't open or create logfile */
    
    Regards,
    
            Joey
    
    --
      / Martin Schulze  *  joeyat_private  *  26129 Oldenburg /
     /                                     http://home.pages.de/~joey/
    /  VFS: no free i-nodes, contact Linus  -- finlandia, Feb '94   /
    
    --xgI/oilGqZ+PHCdU
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    
    iQCVAwUBNRVdRBRNm5Suj3z1AQHGQgP/SvaEy3iuFLC1j/X3gL43YW0n+v0E53KH
    QgzUIJq4H4VFEotHZb1IQ2QN7QUcvdrm+3XYLbMDs+tHHr31yNSGJsejpnmD9MvN
    5kd519Km8UAclEHiVtuc4aj0igDow6GXvtLd7b77COcxA1iXYYoLQhridr7O6a29
    WG3c+7eLFng=
    =7r8s
    -----END PGP SIGNATURE-----
    
    --xgI/oilGqZ+PHCdU--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:46:40 PDT