[2993] in bugtraq
Re: vulnerability in vi under AIX 3.2
daemon@ATHENA.MIT.EDU (Max Bloomfield)
Wed Jul 24 12:46:53 1996
Date: Wed, 24 Jul 1996 03:22:38 -0700
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Max Bloomfield <maxim@ugcs.caltech.edu>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In mlist.bugtraq you write:
>I can not duplicate this on our AIX 3.2.5 machines -- vi only reads
>$HOME/.exrc . Since root's $HOME is /, you've got a bigger problem if folks
>can write to the .exrc.....
If within $HOME/.exrc "set exrc" appears, then ./.exrc will be sourced upon
startup of vi, in AIX 3.2.4. I don't know about 3.2.5, but I suspect that
it is the same.
Max Bloomfield
maxim@ugcs.caltech.edu
maxim@cco.caltech.edu