[4022] in bugtraq
Re: IRIX: Bug in startmidi
daemon@ATHENA.MIT.EDU (Nafees Bin Zafar)
Sun Feb 9 17:05:06 1997
Date: Sun, 9 Feb 1997 15:49:49 -0500
Reply-To: Nafees Bin Zafar <nafees@STONO.CS.COFC.EDU>
From: Nafees Bin Zafar <nafees@STONO.CS.COFC.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <16207.855511905@maxx>
On Sun, 9 Feb 1997, David Hedley wrote:
> Whilst browsing around the filesystem on my SGI (running IRIX 5.3), I
> noticed a little suid-root program called 'startmidi' which hides in
> /usr/sbin. When run, this program creates various files in /tmp. You
> guessed it, it respects umask and follows symlinks. Comme ca:
>
[ ...deletia... ]
--
I was not able to reproduce this phenomenon in irix 6.2 or irix 6.3.
'startmidi' creates a file in /tmp called "midififo", however if a file,
or symlink, exists there already, it simply erases it. The newly
created "midififo" is owned by root, and only root has any kind of
permissions on it. It does not follow sym links.
------Nafees Bin Zafar
<binzafn@musc.edu>
<nafees@cs.cofc.edu>
http://www.cs.cofc.edu/~nafees
"I think, therefore I think"