[634] in bugtraq
Re: Solaris 2.4 bugs...
daemon@ATHENA.MIT.EDU (Robert Lau)
Fri Jan 13 14:48:38 1995
Date: Fri, 13 Jan 1995 09:49:35 -0800
From: Robert Lau <rslau@tarazed.usc.edu>
To: Philippe.Langlois@world-net.sct.fr
Cc: bugtraq@fc.net
In-Reply-To: <199501131200.NAA11279@world-net.sct.fr> "Philippe.Langlois@world-net.sct.fr"
Reply-To: rslau@usc.edu
From: Philippe Langlois <Philippe.Langlois@world-net.sct.fr>
Date: Fri, 13 Jan 1995 13:00:42 +0100 (MET)
Does anybody have information about the Solaris 2.4 bug
fixed in the patch Patch-ID# 102044-01 :
SunOS 5.4: bug in mouse code makes "break root" attack possible
...
The bug was in Solaris 2.3 and yes it was the mouse driver.
I'm still mulling over the propriety of posting the 3 line
C program that expliots this hole and gives any user root.
Robert Lau Systems Programmer, Unix Systems
University Computing Services
213-740-2866 University of Southern California
rslau@usc.edu 1020 W Jefferson, LA, CA USA, 90089-0251