[5288] in bugtraq

home help back first fref pref prev next nref lref last post

Re: CERT Advisory CA-97.23 - rdist

daemon@ATHENA.MIT.EDU (Simon Karpen)
Wed Sep 17 13:01:25 1997

Date: 	Tue, 16 Sep 1997 23:48:21 -0400
Reply-To: Simon Karpen <slk@GRACE.ACM.RPI.EDU>
From: Simon Karpen <slk@GRACE.ACM.RPI.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <199709162341.TAA21019@jekyll.piermont.com>

On Tue, 16 Sep 1997, Perry E. Metzger wrote:

> > > CERT* Advisory CA-97.23
> > > Original issue date: September 16, 1997
> > > Last revised: --
> > >
> > > Topic: Buffer Overflow Problem in rdist
> >
> > OpenBSD does not have this problem.  None of the versions of rdist
> > distributed are setuid or setgid.
>
> NetBSD no longer has suid versions of rdist either.

Neither Debian Linux 1.3.1 nor Redhat Linux 4.2 have setuid
versions of rdist either.

Simon Karpen
karpes@rpi.edu    slk@acm.rpi.edu
"Fixing Unix is easier than living with NT."
                --Larry McVoy

home help back first fref pref prev next nref lref last post