[UNIX] Linux Distributions are Vulnerable to the /bin/login Overflow

Date: 12/20/01

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - - - - - - - -

It seems that while Redhat Linux and Caldera Linux distributions are
immune to the recent /bin/login environment overflow, other Linux
distributions are not. Several Linux distributions install /bin/login with
SysV login options enabled.


Vulnerable systems:
Slackware 8.0
Slackware 4.0
Slackware 3.3
SuSE 6.1

Immune systems:

A quick way to check for SysV option capabilities is to type "login", then
enter "root testenv1=test" at the login: prompt. Supply your root passwd,
and look for "testenv1" in the output of set. If it is set, then your copy
of /bin/login supports SysV options, and is probably vulnerable.


The information has been provided by <mailto:a_rager@yahoo.com> Anton


