[22929] in bugtraq
Re: Mac OS X setuid root security hole
daemon@ATHENA.MIT.EDU (Chris Adams)
Sat Oct 20 04:02:20 2001
Date: Sat, 20 Oct 2001 00:23:07 -0700
Content-Type: text/plain; charset=US-ASCII; format=flowed
Mime-Version: 1.0 (Apple Message framework v472)
From: Chris Adams <chris@improbable.org>
To: bugtraq@securityfocus.com
Content-Transfer-Encoding: 7bit
In-Reply-To: <5.1.0.14.2.20011017124659.02820020@mail.biapo.com>
Message-Id: <4EE93B46-C52B-11D5-BA66-0003931044DC@improbable.org>
On Wednesday, October 17, 2001, at 09:53 , rotaiv wrote:
> Try these steps on an OS X machine (not logged in as root)
>
> - Open up the terminal application
> - Quit the terminal application
> - Open up NetInfo Manager (leave it in the foreground)
> - Open up the Terminal application form the "Recent Items" list in the
> Apple Menu.
Apple's Software Update app has a vaguely-described "Security Update
10-19-01" which fixes this problem.
Chris