[27018] in bugtraq

home help back first fref pref prev next nref lref last post

Re: xbreaky symlink vulnerability

daemon@ATHENA.MIT.EDU (Jeremy C. Reed)
Thu Sep 12 14:30:00 2002

Date: Thu, 12 Sep 2002 10:47:38 -0700 (PDT)
From: "Jeremy C. Reed" <reed@reedmedia.net>
To: bugtraq@securityfocus.com
In-Reply-To: <3D80C09E.4552614E@obit.nl>
Message-ID: <Pine.LNX.4.43.0209121040260.26575-100000@pilchuck.reedmedia.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Thu, 12 Sep 2002, Marco van Berkum wrote:

> from http://xbreaky.sourceforge.net. xbreaky is added to the OpenBSD
> ports tree, NetBSD tree and possibly others.

Nevertheless, the NetBSD pkgsrc for xbreaky patches the Makefile so it
doesn't install 6755. According to cvs for games/xbreaky, it has been this
way since it was added to the NetBSD packages collection in October, 2000.

install -c -s -o root -g wheel -m 555 xbreaky      /usr/X11R6/bin

$ ls -l /usr/X11R6/bin/xbreaky
-r-xr-xr-x  1 root  wheel  82260 Sep 12 10:39 /usr/X11R6/bin/xbreaky

   Jeremy C. Reed
   http://bsd.reedmedia.net/


home help back first fref pref prev next nref lref last post