[3758] in bugtraq
Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm]
daemon@ATHENA.MIT.EDU (Casper Dik)
Fri Dec 6 13:58:52 1996
Date: Fri, 6 Dec 1996 18:02:38 +0100
Reply-To: Casper Dik <casper@holland.Sun.COM>
From: Casper Dik <casper@holland.Sun.COM>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To: Your message of "Fri, 06 Dec 1996 12:20:34 GMT."
<20509.199612061220@gpo.gb.swissbank.com>
>>Problem: Vulnerabilities in /usr/vmsys/bin/chkperm
>>Platform: Solaris 2.4, 2.5, 2.5.1, other System V derived
>> systems with the FACE package installed
>
>Of interest to the full disclosure argument, I reported this to Sun
>more than a year ago.
Teh bug is actually fixed in 2.5 and 2.5.1, though they seem to have
broken the program in the process. [ a line of code was dropped
inadvertedly ]
I don't know why this was never made into a patch.
(And the fact that the program is now broken and nobody reported a bug on it,
makes me wonder ....)
Casper