[8730] in bugtraq
wordperfect 8 for linux security
daemon@ATHENA.MIT.EDU (Edsel Adap)
Fri Dec 18 23:18:07 1998
Date: Fri, 18 Dec 1998 11:47:45 -0500
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Edsel Adap <adap@ADAP.ORG>
To: BUGTRAQ@NETSPACE.ORG
Hi,
I sent a similar message to Corel about this. And I figured I'd send
it out here in order to prevent people from opening up their systems by
installing word perfect 8 before the problem is fixed.
When wordperfect 8 is installed it creates a /tmp/wpc-<hostname>
directory with permissions 777. And all files inside of it are mode
666. And when these files are created, symlinks are followed.
You already know what this means when root tries to install word
perfect.
So to those of you who are planning to install word perfect 8 for
linux, don't do it as root. Pick another user for doing the job.
--
Edsel Adap
edsel@adap.org
http://www.adap.org/~edsel/ LINUX - the choice of the GNU generation
"Netscape is an application which grows to fill all available memory." - me