Re: Fwd: Multiple vendor 'Taylor UUCP' problems.

From: Andrey A. Chernov (ache@nagual.pp.ru)
Date: 09/09/01


Date: Sun, 9 Sep 2001 06:04:26 +0400
From: "Andrey A. Chernov" <ache@nagual.pp.ru>
To: Kris Kennaway <kris@obsecurity.org>


On Sat, Sep 08, 2001 at 19:01:03 -0700, Kris Kennaway wrote:
> uucp binaries in question. uustat is executed by default by root in
> /etc/periodic.

uustat must be executed by 'su -m uucp' in any case.

> There are other consequences of the underlying vulnerability (full
> read/write access to the /var/spool/uucp directories, for example), so

It can't be fixed without total UUCP redesign, it is their problem, not
ours.

-- 
Andrey A. Chernov
http://ache.pp.ru/

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: Fwd: Multiple vendor Taylor UUCP problems.
    ... > as the uucp user through specifying a custom configuration file - see ... > like uustat, which is called daily by /etc/periodic. ... Is there really any reason to run uustat as root? ...
    (FreeBSD-Security)
  • Re: Fwd: Multiple vendor Taylor UUCP problems.
    ... On Sat, 8 Sep 2001, Kris Kennaway wrote: ... These flaws in the UUCP suite need to be documented, ... If uustat being called from the daily scripts is the exploit "vector", ...
    (FreeBSD-Security)
  • Redhat 7.0 local root (via uucp) (attempt 2)
    ... Redhat 7.0 local root ... An earlier versionof makewhatis had a fault in the handling of ... compressed files that allowed execution of arbitrary commands as root. ... Taylor UUCP package and uucp exploit. ...
    (Bugtraq)
  • Strange behavior of serial port / uucp on FC3 after recent updates
    ... I've been using uucp for years with no trouble until just recently. ... minicom will work if I run it as root; cu fails regardless of whether ... I run it as a user or root. ... What's really strange is cuwill start ...
    (Fedora)
  • Re: What the logic to group ownership?
    ... >what difference does it makes if the group is root, bin, sys, other ... The group ownership is largely ... >which have a group of uucp, but since the permissions are still 555, ...
    (comp.unix.solaris)

Quantcast