[176] in linux-security and linux-alert archive

home help back first fref pref prev next nref lref last post

DIP suid security problem

daemon@ATHENA.MIT.EDU (Benedikt Stockebrand)
Sat Mar 18 12:03:09 1995

Date: Tue, 14 Mar 1995 01:40:36 +0100
From: Benedikt Stockebrand <benedikt@devnull.ping.de>
To: linux-security@tarsier.cv.nrao.edu
Cc: volkerdi@mhd1.moorhead.msus.edu


I don't know if this is already known but the Slackware 2.1.0
distribution has a security problem with dip (dip-3.3.7i) set suid
root and world executable.  Using the -v option shows you the password
used to connect to the remote host.


    Ben

-----------------------------------------------------------------------
Benedikt (Ben) Stockebrand (benedikt@devnull.ping.de) Dortmund, Germany
          And don't tell me about Benedict Arnold anymore...
-----------------------------------------------------------------------


home help back first fref pref prev next nref lref last post