[2124] in bugtraq
Re: BUGTRAQ ALERT: Solaris 2.x vulnerability
daemon@ATHENA.MIT.EDU (Casper Dik)
Thu Aug 17 18:58:22 1995
Date: Thu, 17 Aug 1995 13:41:36 +0200
Reply-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
From: Casper Dik <casper@Holland.Sun.COM>
X-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@CRIMELAB.COM>
In-Reply-To: Your message of "Wed, 16 Aug 1995 20:10:25 PDT."
<199508170310.UAA06542@statler.csc.calpoly.edu>
Just to add my two cents to the discussion:
- this is a known problem
- it is fixed in 2.5 (by using fchown, not chown, both versions of ps)
- it only affects people that either:
- use tmpfs (default) and don't modifiy it +t themselves
- or us a filesystem for /tmp and didn't do a +t as well.
Casper