[11405] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Question on Solaris LC_MESSAGES libc exploit

daemon@ATHENA.MIT.EDU (acpizer)
Wed Aug 18 03:58:40 1999

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.NEB.3.96.990817094159.18141A-100000@mach.unseen.org>
Date:         Tue, 17 Aug 1999 09:47:24 +0100
Reply-To: acpizer <acpizer@MACH.UNSEEN.ORG>
From: acpizer <acpizer@MACH.UNSEEN.ORG>
X-To:         bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM

>I am still able to gain root with the below code
>on Sparc Solaris 7 5/99 Release boxes with MU2 and 7_Recommended patch set
>installed (offset 7152 gets root for me). Has there been a patch released
>for Solaris 7 that addresses this? Thanks for any help.

Casper Dik's *unofficial* patch will fix this...
http://www.geek-girl.com/bugtraq/1999_2/0535.html

how long does it take Sun to come up with something more useable/tested?


Cheers.


-------------------------------------------------------------------------------
"Probably you've only really grown up, when you can bear not being understood."

                              Marian Gold /Alphaville

home help back first fref pref prev next nref lref last post