RE: openbsd 3.4 ps bug

From: thanos F_at_rm@k1s (F_at_rm@k1s)
Date: 11/21/03

  • Next message: Sverre H. Huseby: "Re: Can you exploit this XSS?"
    Date: 21 Nov 2003 08:51:18 -0000
    To: vuln-dev@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    This is the reply mail from the openbsd project.

    -------------------------------------------------------------------
    From :
    "Todd C. Miller" <Todd.Miller@courtesan.com>
    To : "sfdodgfs 54tftdsg" <fsvsunix@hotmail.com>
    CC : bugs@openbsd.org
    Subject :Re: Openbsd 3.4 ps utility bug found
    Date :Mon, 17 Nov 2003 12:58:29 -0700
     
    This is not a security flaw per se since ps is not setuid or setgid
    and the bug only applies when you try to specify a memory file and
    swap file on the command line.

    That said, I have found the bug and will commit a fix.

     - todd

    --------------------------------------------------------------------

    This clears up that the bug is not exploitable.


  • Next message: Sverre H. Huseby: "Re: Can you exploit this XSS?"

    Relevant Pages

    • Re: DNS Scavenging not working
      ... I'd clear the checks off the boxes for scavenging, restart the DNS service. ... Maybe a bug. ... Todd J Heron, MCSE ...
      (microsoft.public.windows.server.dns)
    • Re: Graphical windows auto-maximizing - annoying
      ... On 29 May 2008, at 20:06, Todd N wrote: ... Sounds like a bug to me, doesn't do it here anyway (GNOME 2.22 on ... Solaris). ...
      (GNOME)
    • Re: Short (DOS) names for paths in environment variables
      ... Todd, %~sX works for me. ... Where can I learn more about the bug you mentioned? ... perhaps the exact circumstance which triggers the ~s bug ... contact Simon Sheppard. ...
      (microsoft.public.win2000.cmdprompt.admin)
    • Re: Excel round function
      ... if your device oem offers that rom update, you are in luck, otherwise, Todd is correct. ... Anyone else old enough to remember Intel's math coprocessor bug... ...
      (microsoft.public.pocketpc)