[3758] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm]

daemon@ATHENA.MIT.EDU (Casper Dik)
Fri Dec 6 13:58:52 1996

Date:         Fri, 6 Dec 1996 18:02:38 +0100
Reply-To: Casper Dik <casper@holland.Sun.COM>
From: Casper Dik <casper@holland.Sun.COM>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To:  Your message of "Fri, 06 Dec 1996 12:20:34 GMT." 
              <20509.199612061220@gpo.gb.swissbank.com>

>>Problem: Vulnerabilities in /usr/vmsys/bin/chkperm
>>Platform: Solaris 2.4, 2.5, 2.5.1, other System V derived
>>          systems with the FACE package installed
>
>Of interest to the full disclosure argument, I reported this to Sun
>more than a year ago.


Teh bug is actually fixed in 2.5 and 2.5.1, though they seem to have
broken the program in the process.  [ a line of code was dropped
inadvertedly ]

I don't know why this was never made into a patch.

(And the fact that the program is now broken and nobody reported a bug on it,
makes me wonder ....)

Casper

home help back first fref pref prev next nref lref last post