[6852] in bugtraq

home help back first fref pref prev next nref lref last post

SECURITY: Red Hat Linux 5.1 linuxconf bug

daemon@ATHENA.MIT.EDU (Michael K. Johnson)
Thu May 28 16:57:11 1998

Date: 	Thu, 28 May 1998 11:02:16 -0400
Reply-To: johnsonm@REDHAT.COM
From: "Michael K. Johnson" <johnsonm@REDHAT.COM>
X-To:         redhat-announce-list@redhat.com
To: BUGTRAQ@NETSPACE.ORG

In Red Hat Linux 5.1, linuxconf version 1.11r11-rh2 was inadvertantly
setuid root.  This creates the potential for security holes that allow
attackers to gain root access to your machine.  (Users of Red Hat
Linux 5.0 and earlier are NOT affected, as linuxconf was not included
with any previous version of Red Hat Linux.)

If you have installed Red Hat Linux 5.1, you can immediately remove
the danger by logging in as root and running the command:

        chmod -s /bin/linuxconf

We also recommend that you update to the latest version of linuxconf,
linuxconf-1.11r11-rh3, which fixes this bug.

Red Hat Linux 5.1 for Intel:
rpm -Uvh ftp://ftp.redhat.com/updates/5.1/i386/linuxconf-1.11r11-rh3.i386.rpm

Red Hat Linux 5.1 for Alpha:
rpm -Uvh ftp://ftp.redhat.com/updates/5.1/alpha/linuxconf-1.11r11-rh3.alpha.rpm

Thanks to BUGTRAQ for finding and reporting this.

home help back first fref pref prev next nref lref last post