[2240] in bugtraq
Re: load.root (loadmodule hole)
daemon@ATHENA.MIT.EDU (Fred Blonder)
Fri Sep 15 18:48:24 1995
Date: Fri, 15 Sep 1995 17:17:35 -0400
Reply-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
From: Fred Blonder <fred@nasirc.hq.nasa.gov>
X-To: Bugtraq List <BUGTRAQ@CRIMELAB.COM>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@CRIMELAB.COM>
In-Reply-To: Your message of "Fri, 15 Sep 1995 15:44:04 +0200."
<Pine.HPP.3.91.950915154032.10301A-100000@statt.ericsson.se>
Am I overlooking something obvious here, or would simply turning off the
set-UID bit on "loadmodule" be an acceptable temporary workaround for
most sites?
-----
Fred Blonder fred@nasirc.hq.nasa.gov
Hughes STX Corp. (301) 441-4079
7701 Greenbelt Rd.
Greenbelt, Md. 20770