Re: XFree86 vulnerability exploit

From: Adam Langley (agl_at_imperialviolet.org)
Date: 02/13/04

  • Next message: bugzilla_at_redhat.com: "[RHSA-2004:059-01] Updated XFree86 packages fix privilege escalation vulnerability"
    Date: Fri, 13 Feb 2004 11:36:46 +0000
    To: Bender <bender2@sdf.lonestar.org>
    
    

    On Wed, Feb 11, 2004 at 11:09:00AM +0000, Bender wrote:
    > Below you can find a exploit for latest bug in XFree86 sofware.
    > Tested on some versions of RedHat Linux (mainly 7.0).
    > regards
    > Bender
    >
    > execle("/usr/bin/X11/X","X",":0","-fp","/tmp",0,envp);

    It's worth pointing out that this is still a problem for installations which
    do not have a SUID root. (For example, the X server is started by a display
    manager which is already root).

    If you can send commands to the X server you can:
    % xset +fp /path/to/bad/fontdir

    Which has the same effect (comfirmed).

    -- 
    Adam Langley                                      agl@imperialviolet.org
    http://www.imperialviolet.org                       (+44) (0)7906 332512
    PGP: 9113   256A   CC0F   71A6   4C84   5087   CDA5   52DF   2CB6   3D60
    

  • Next message: bugzilla_at_redhat.com: "[RHSA-2004:059-01] Updated XFree86 packages fix privilege escalation vulnerability"

    Relevant Pages

    • Re: Putting server on the internet or not
      ... The question is - is it worth pointing the IP addresses directly at my server, and hosting my mail and http directly from this server, or would it be considered smarter to have everything hosted at the ISP still? ... With the web site also, if I hosted this myself, I could finally do some dynamic web pages, whereas previously I'd be stuck with standard .html pages at my ISP. ...
      (Fedora)
    • Re: Putting server on the internet or not
      ... The question is - is it worth pointing the IP addresses directly at my server, and hosting my mail and http directly from this server, or would it be considered smarter to have everything hosted at the ISP still? ... a family server running DNS, all of my family's email, a website, and an ...
      (Fedora)
    • Putting server on the internet or not
      ... The question is - is it worth pointing the IP addresses directly at my server, and hosting my mail and http directly from this server, or would it be considered smarter to have everything hosted at the ISP still? ... With the web site also, if I hosted this myself, I could finally do some dynamic web pages, whereas previously I'd be stuck with standard .html pages at my ISP. ...
      (Fedora)
    • Re: Putting server on the internet or not
      ... >> The question is - is it worth pointing the IP addresses directly at my ... >> server, and hosting my mail and http directly from this server, or would ... >> it be considered smarter to have everything hosted at the ISP still? ... is a smoothwall firewall between your server and the ...
      (Fedora)
    • Re: I can receive e-mail but i cant SEND
      ... "raymond foster shelton" wrote: ... "Bender" wrote ... An unknown error has occurred. ... 'mail.charter.net', Server: 'mail.charter.net', Protocol: SMTP, Server ...
      (microsoft.public.windows.vista.mail)

  • Quantcast