[5288] in bugtraq
Re: CERT Advisory CA-97.23 - rdist
daemon@ATHENA.MIT.EDU (Simon Karpen)
Wed Sep 17 13:01:25 1997
Date: Tue, 16 Sep 1997 23:48:21 -0400
Reply-To: Simon Karpen <slk@GRACE.ACM.RPI.EDU>
From: Simon Karpen <slk@GRACE.ACM.RPI.EDU>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <199709162341.TAA21019@jekyll.piermont.com>
On Tue, 16 Sep 1997, Perry E. Metzger wrote:
> > > CERT* Advisory CA-97.23
> > > Original issue date: September 16, 1997
> > > Last revised: --
> > >
> > > Topic: Buffer Overflow Problem in rdist
> >
> > OpenBSD does not have this problem. None of the versions of rdist
> > distributed are setuid or setgid.
>
> NetBSD no longer has suid versions of rdist either.
Neither Debian Linux 1.3.1 nor Redhat Linux 4.2 have setuid
versions of rdist either.
Simon Karpen
karpes@rpi.edu slk@acm.rpi.edu
"Fixing Unix is easier than living with NT."
--Larry McVoy