Re: FreeBSD Security Advisory: FreeBSD-SA-01:11.inetd [REVISED]

From: Kris Kennaway (kris@obsecurity.org)
Date: 01/30/01


Date: Mon, 29 Jan 2001 22:29:03 -0800
From: Kris Kennaway <kris@obsecurity.org>
To: "Brian F. Feldman" <green@FreeBSD.ORG>


On Tue, Jan 30, 2001 at 01:09:11AM -0500, Brian F. Feldman wrote:
> Actually, there were two issues. One was that the permissions weren't
> dropped totally on the way to opening the .fakeid file, and the other was
> that it was not read in a way that would be guaranteed not to block, so by
> creating a named pipe, the user could hang an inetd child.

Is that really a security issue, though?

Kris



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: FreeBSD Security Advisory: FreeBSD-SA-01:11.inetd [REVISED]
    ... One was that the permissions weren't ... dropped totally on the way to opening the .fakeid file, ... The advisory really should incorporate at least both ...
    (FreeBSD-Security)
  • Re: FreeBSD Security Advisory: FreeBSD-SA-01:11.inetd [REVISED]
    ... One was that the permissions weren't ... >> dropped totally on the way to opening the .fakeid file, ... the user could hang an inetd child. ...
    (FreeBSD-Security)
  • Re: Username and Usergroup
    ... My question was actually for jokobe - as to why he/she feels they need to ... I can see if they are setting permissions on ... > You have a valid point about the security permissions for running queries ... >> So why are you trapping that when opening the db? ...
    (microsoft.public.access.formscoding)
  • Re: Ow! Dont put your Thumb there!
    ... Turn off thumbnails in Windows Explorer and stop opening your local FP site outside of FP ... | "Server error: The server extensions were unable to ... | Well, if I could find the file to check the permissions, ...
    (microsoft.public.frontpage.programming)
  • Re: Probs accessing database for users of newly developed Superuse
    ... see anything that might prevent certain users from opening the db. ... Both users are listed as members of Superuser. ... I accidently selected the User and Group Permissions window and when I tried ... "You can't view this object's permissions. ...
    (microsoft.public.access.security)

Quantcast