Re: Corel Linux 1.0 dosemu default configuration: Local root vuln

From: VaMPiRe, WHiTe (whitvampat_private)
Date: Thu Mar 02 2000 - 23:54:17 PST

  • Next message: Kuji: "Pocsag remote access to client can't be disabled."

    --vOmOzSkFvhd7u8Ms
    Content-Type: text/plain; charset=us-ascii
    Content-Transfer-Encoding: quoted-printable
    
    On Thu, Mar 02, 2000 at 04:47:11AM +0000, suidat_private(suidat_private) wrote:
    <snip>
    : Summary:
    :=20
    : 	Local users can take advantage of a packaging and configuration
    : 	error (which has been known and documented for a long time) to
    : 	execute arbitrary commands as root.
    :=20
    : 	We see from the doc/README/SECURITY file as well as
    : 	http://www.dosemu.org/docs/README/0.98/README-3.html
    : 	written in 1997 that this configuration is bad.
    <snip>
    
    	Tested default configuration of dosemu on Slackware 7.0, no
    vulnerability.
    
    Regards,
    --=20
        __      ______   ____
       /  \    /  \   \ /   / WHiTe VaMPiRe\Rem
       \   \/\/   /\   Y   /  whitevampireat_private
        \        /  \     /   http://www.projectgamma.com/
         \__/\  /    \___/    http://www.gammaforce.org/
              \/ "Silly hacker, root is for administrators."
    
    --vOmOzSkFvhd7u8Ms
    Content-Type: application/pgp-signature
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 6.5.1
    
    iQA/AwUBOL9vp9/q8ZpxA8pfEQKkdwCgwh68tX6NWe21l9JLkhIb3JEtAn4AnAtR
    Frbg9nvoZiReJxpso6qhQu2w
    =D8oK
    -----END PGP SIGNATURE-----
    
    --vOmOzSkFvhd7u8Ms--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:38:55 PDT