[24326] in bugtraq
Re: Another local root vulnerability during installation of Tarantella
daemon@ATHENA.MIT.EDU (Larry W. Cashdollar)
Tue Feb 19 18:32:23 2002
Date: Tue, 19 Feb 2002 12:05:39 -0500 (EST)
From: "Larry W. Cashdollar" <lwc@vapid.dhs.org>
To: <bugtraq@securityfocus.com>
In-Reply-To: <20020219082130.S5498-100000@vapid.dhs.org>
Message-ID: <20020219120418.M5926-100000@vapid.dhs.org>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
> Recommendations:
> I again recommend the target system is running in single user mode before this
> software is installed.
>
I forgot to mention, you might want to make sure /tmp is clear of
malicious symlinks after you boot to run level 1 and before you install
the Tarantella.
-- Larry C$