[527] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Yesterday this would have worked... (fwd)

daemon@ATHENA.MIT.EDU (der Mouse)
Sat Dec 17 08:50:04 1994

Date: Sat, 17 Dec 1994 07:34:50 -0500
From: der Mouse <mouse@Collatz.McRCIM.McGill.EDU>
To: bugtraq@fc.net

> Here is the original message posted with permission, 10 points to
> anyone who can spot the supposed flaw in the BSDI O/S with this.

Looks to me as though exec() sets the UID on the process per setuid
bits before it checks for arguments too long, and doesn't take care to
undo this properly in that case.

> BTW, anyone care to comment if this should be replicable across
> platforms?

Depends on where the bug came from.  If it's one of those ever-since-V7
bugs it should be widespread; if it's a fumble-fingers mistake from
BSDI it's probably not elsewhere.  I'm sure everyone can imagine
variations.  I'm certainly going to test _my_ systems!

					der Mouse

			    mouse@collatz.mcrcim.mcgill.edu

home help back first fref pref prev next nref lref last post