[5949] in RedHat Linux List

home help back first fref pref prev next nref lref last post

problems with /usr/X11/bin/SuperProbe being setuid

daemon@ATHENA.MIT.EDU (Simon Karpen)
Mon Nov 25 02:43:45 1996

Date: 	Mon, 25 Nov 1996 02:42:01 -0500 (EST)
From: Simon Karpen <slk@karpes.stu.rpi.edu>
To: redhat-list@redhat.com
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

this is off the bugtraq list. a recommendation to everybody: remove the
setuid bit from /usr/X11/bin/SuperProbe. I'd say this belongs in errata.

Simon Karpen
karpes@rpi.edu, slk@acm.rpi.edu, slk@karpes.stu.rpi.edu
"I'm not paranoid, it's just that everybody's out to get me."
			--Linus Torvalds

---------- Forwarded message ----------
Date: Mon, 25 Nov 1996 00:03:53 -0600
From: Marc Slemko <marcs@alive.ampr.ab.ca>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
Subject: cvs commit:  ports/x11/XFree86 Makefile (fwd)


As per the below commit, SuperProbe is no longer setuid root on FreeBSD.
I would highly recommend that you remove the setuid bit if it is installed
on your system; it is normally in /usr/X11R6/bin/SuperProbe if you have X
installed.  'chmod u-s /usr/X11R6/bin/SuperProbe' will do the trick.

There are at least two possible buffer overflows which are trivial to find
by looking through the source.  I have not investigated them fully to
determine if they are exploitable; they are not exploitable using the more
common methods, but they could still be exploitable.

By removing the setuid bit, the net result is that non-root users can't
probe your video chip.  Funny, but to me that is a good thing not a bad
thing.

---------- Forwarded message ----------
Date: Sun, 24 Nov 1996 18:29:27 -0800 (PST)
From: Jean-Marc Zucconi <jmz@freefall.freebsd.org>
To: CVS-committers@freefall.freebsd.org, cvs-all@freefall.freebsd.org,
    cvs-ports@freefall.freebsd.org
Subject: cvs commit:  ports/x11/XFree86 Makefile

jmz         96/11/24 18:29:27

  Modified:    x11/XFree86  Makefile
  Log:
  Remove the suid bit of SuperProbe.
  According to Marc Slemko (marcs@alive.ampr.ab.ca) there are potential
  security holes in SuperProbe and it is not going to be setuid in the
  next release.

  Revision  Changes    Path
  1.23      +2 -1      ports/x11/XFree86/Makefile


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post