[6555] in bugtraq

home help back first fref pref prev next nref lref last post

Qcam : Actually seems to be generic libqcam bug

daemon@ATHENA.MIT.EDU (Alan Cox)
Mon Apr 20 20:23:16 1998

Date: 	Mon, 20 Apr 1998 20:50:06 +0100
Reply-To: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
From: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
X-To:         bst@INAME.COM
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <199804201814.OAA06680@server2.microstar.com.ar> from
              "bst@INAME.COM" at Apr 20, 98 02:14:35 pm

> More Sunsite buggy soft:
>
>    - ftp://sunsite.unc.edu/pub/Linux/apps/video/qcam-0.7c-5.tar.gz
>    - ftp://sunsite.unc.edu/pub/Linux/apps/video/sqcam-0.1.tar.gz

This extends throughout every libqcam based application I've looked at
so far including the SANE-0.67 scanner package, which is often installed setuid
for 'safe' setuid targets like generic scsi.

None of them open the lock file safely.

Alan

home help back first fref pref prev next nref lref last post