HP-UX 11.0 /usr/lbin/rwrite

From: btat_private
Date: Fri May 02 2003 - 10:16:53 PDT

  • Next message: Ed Carp: "RE: [Full-Disclosure] Slow Internet?"

    Hi!
    
    There is a vulnerability in /usr/lbin/rwrite on HP-UX 11.0 (other versions might be vulnerable too).
    
    /usr/lbin/rwrite is installed setuid to root by default.
    
    $ /usr/lbin/rwrite something `perl -e 'print "A" x 14628'` something
    Segmentation fault
    
    Solution : remove setuid bit until patch is available.
    
    Tried to contact security-alertat_private , got "Client rejected. Access denied".
    
    Bye,
    
    btat_private
    <--------------------===========================-------------------->
    Meiles zinutes sirdies damai ar riteriui: siusk MEILE numeriu 1325.
    Jei siunti draugui, po zodzio MEILE nurodyk jo mob. telefono numeri.
    Zinutes kaina 1 Lt.  http://sms.delfi.lt/
    



    This archive was generated by hypermail 2b30 : Fri May 02 2003 - 12:28:34 PDT