Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)

From: Chris Evans (chrisat_private)
Date: Mon Jun 01 1998 - 09:58:24 PDT

  • Next message: Yaron Yanay: "AIX : "/" is owned by bin.bin"

    Hi!!
    
    Someone wrote:
    
    > the binary RPMs have always been shipped with suid linuxconf. Does this
    >announce mean that linuxconf has been found insecure, so that is MUST not
    >be used suid ? I haven't seen anything about linuxconf on BUGTRAQ, apart
    >from your posting.
    
    I alerted RedHat to the insecurity in a suid root linuxconf. I didn't cc:
    to bugtraq (only the xosview got cc:'ed here which still isn't fixed).
    
    
    Now RedHat have a fixed rpm out, I suppose I had better spill the beans.
    
    Set environment variable "LANG" to a long string (about 1k should do it).
    Run linuxconf. Watch crash. Smile.
    
    Note that discovery of this problem was trivial.
    
    Most importantly, please note that there are probably plenty of other
    security holes in linuxconf apart from this one.
    
    Cheers
    Chris
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:55:57 PDT