[6555] in bugtraq
Qcam : Actually seems to be generic libqcam bug
daemon@ATHENA.MIT.EDU (Alan Cox)
Mon Apr 20 20:23:16 1998
Date: Mon, 20 Apr 1998 20:50:06 +0100
Reply-To: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
From: Alan Cox <alan@LXORGUK.UKUU.ORG.UK>
X-To: bst@INAME.COM
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <199804201814.OAA06680@server2.microstar.com.ar> from
"bst@INAME.COM" at Apr 20, 98 02:14:35 pm
> More Sunsite buggy soft:
>
> - ftp://sunsite.unc.edu/pub/Linux/apps/video/qcam-0.7c-5.tar.gz
> - ftp://sunsite.unc.edu/pub/Linux/apps/video/sqcam-0.1.tar.gz
This extends throughout every libqcam based application I've looked at
so far including the SANE-0.67 scanner package, which is often installed setuid
for 'safe' setuid targets like generic scsi.
None of them open the lock file safely.
Alan