[14274] in bugtraq

home help back first fref pref prev next nref lref last post

Re: TESO advisory -- wmcdplay

daemon@ATHENA.MIT.EDU (Wichert Akkerman)
Tue Mar 14 19:03:26 2000

Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
              protocol="application/pgp-signature"; boundary="Dxnq1zWXvFF0Q93v"
Message-Id:  <20000314012945.A21408@mors.net>
Date:         Tue, 14 Mar 2000 01:29:45 +0100
Reply-To: Wichert Akkerman <wichert@CISTRON.NL>
From: Wichert Akkerman <wichert@CISTRON.NL>
X-To:         krahmer@CS.UNI-POTSDAM.DE
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <20000311143230.4C0C01EE8B@lists.securityfocus.com>; from
              krahmer@CS.UNI-POTSDAM.DE on Sat, Mar 11, 2000 at 06:32:30AM -0800

--Dxnq1zWXvFF0Q93v
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Previously krahmer@CS.UNI-POTSDAM.DE wrote:
> Systems Affected
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
>=20
>     Any system which has wmcdplay installed as setuid root. Though on most
>     popular system distributions wmcdplay is not installed by default, the
>     optional installation of it is always setuid root, hence affected by =
the
>     problem.

[.. snip snip ..]
=20
>       Debian/GNU Linux 2.1, wmcdplay 1.0beta1-2

Unlike what you imply here Debian does not ship wmcdplay setuid root.

Wichert.

--=20
   ________________________________________________________________
 / Generally uninteresting signature - ignore at your convenience  \
| wichert@liacs.nl                    http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |

--Dxnq1zWXvFF0Q93v
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjjNh/kACgkQPLiSUC+jvC1O8ACeJSK+9XHoU2t8kW80mzvq8adU
dJYAnRMjCM9cQrj/qLHeivGagY2JKhwH
=KE91
-----END PGP SIGNATURE-----

--Dxnq1zWXvFF0Q93v--

home help back first fref pref prev next nref lref last post