Re: tar/security best practice (was Re: RE: Is FreeBSD's tar susceptible to this?)

From: Brett Glass (brett@lariat.org)
Date: 10/02/02


Date: Tue, 01 Oct 2002 17:10:23 -0600
To: "f.johan.beisser" <jan@caustic.org>
From: Brett Glass <brett@lariat.org>

At 04:56 PM 10/1/2002, f.johan.beisser wrote:

>i guess i would be more worried about this having the ability to execute
>arbitrary code as the user; which it doesn't seem to have.

There are dozens of ways that it can. Think ~/.forward with a piped
command, for example.

--Brett

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: 1.9 Patch notes
    ... >* Execute - Improved Execute and other discounts to the Execute ability ... >* Mace Specialization - The stun effect's duration no longer diminishes ... >is diminished by controlled stun abilities and spells (e.g. Cheap Shot, ...
    (alt.games.warcraft)
  • Re: [Full-disclosure] Cisco IOS Shellcode Presentation
    ... what code that product should be allowed to execute. ... Hardware has bugs too. ... Arbitrary code execution isn't too hard on the XBox, for instance, even ... that constantly needs feeding, whether it is on a funny-looking ...
    (Full-Disclosure)
  • Re: /lib/ld-2.2.4.so
    ... > user doesn't have the permission to execute, it is enough to have read ... security of your system on the inability of users to run arbitrary code ... arbitrary code (from various features of ld.so, to programs like gdb, to ... I mean programs whose vulnerabilities (and features) are "mostly ...
    (Vuln-Dev)
  • Re: Oh...MY...GOD...ROID RAGE!!
    ... and tend to execute them. ... Our ability to punish outstrips our ability to ... Their ability to discern judgment ...
    (misc.fitness.weights)
  • Re: SqlDataSource with multiple data tables
    ... accomplish this with 2 separate SqlDataSources), ... execute these two queries independently. ... Revert back to DataSet's ability to store and retrieve ... multiple tables and the ability to create DataRelations? ...
    (microsoft.public.dotnet.framework.adonet)

Quantcast