Re: FreeBSD 3.3 gated-3.1.5 local exploit

From: Kris Kennaway (krisat_private)
Date: Wed Dec 01 1999 - 11:32:52 PST

  • Next message: Alec Kosky: "Re: HP Secure Web Console"

    On Tue, 30 Nov 1999, Brock Tellier wrote:
    
    > /usr/local/bin/gdc contains a buffer overflow that may ONLY be exploited
    > by the group 'wheel'.  According to the man page the default group is
    > "gdmaint", but it was not installed this way by default on my system, nor
    > were any instructions given to make a gdmaint group.  The overflow comes
    
    This is a problem, but it's not just with FreeBSD - obviously if you
    follow these instructions then you're just giving root to members of
    gdmaint, not wheel (which may in fact be worse, if you trust people to use
    gdc who you don't trust with the wheel bit (i.e. those who can legally su
    to root if they knew the password)).
    
    Kris
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:16:12 PDT