Re: Samba 3.x + kernel 2.6.x local root vulnerability

From: Felipe Franciosi (ozzybugt_at_terra.com.br)
Date: 02/10/04

  • Next message: Khalid J Hosein: "Re: clamav 0.65 remote DOS exploit"
    Date: Mon, 09 Feb 2004 22:07:46 -0200
    To: Michal Medvecky <M.Medvecky@sh.cvut.cz>
    
    

    This is old news.

    NFS is also affected by this CONFIGURATION PROBLEM (not a bug). What I
    think might be a problem is this:

    [...took_from_mount_man...]
    OPTIONS
    [...]
            nosuid Do not allow set-user-identifier or set-group-identifier
                    bits to take effect. (This seems safe, but is in fact
                    rather unsafe if you have suidperl(1) installed.)
    [...end_of_cut...]

    I have never tried to use suidperl to "exploit" such thing, but my guess
    is that suidperl somehow "see" the suid bit and can execute scripts set-
    uid-ing the process... or maybe the man mount page was just talking
    about some old suidperl bug... if someone knows, please tell me.

    Best Regards,
    Felipe

    -- 
    Felipe Franciosi <ozzybugt@terra.com.br>
    

  • Next message: Khalid J Hosein: "Re: clamav 0.65 remote DOS exploit"

    Relevant Pages

    • Re: Problem with kerberos and ssh.
      ... kerberos bug or configuration problem. ... Essentially the problem was that ssh is calling ... that is an opaque type (it might be a void *, ...
      (comp.protocols.kerberos)
    • Missing "Add Inherited Form" Menu item
      ... Is this a bug in the beta? ... since i didn't turn up anything about it on Google. ... I'm assuming it's some kind of configuration problem on my end. ...
      (microsoft.public.dotnet.languages.csharp)

  • Quantcast