Hi,

On 25 Apr 2002, Alexandru Balan wrote:

> ba.. deci don't shoot da' keygen nu e apropos de ssh ?

 I'm not shootin', just hunting (see signature)...

> si sshd-u meu e configurat sa nu permita root login 

 Nu are a face, si e vorba de keyinit, de fapt. Din
"FreeBSD-SA-02:23.stdio":

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

II.  Problem Description

Some programs are set-user-id or set-group-id, and therefore run with
increased privileges.  If such a program is started with some of the
stdio file descriptors closed, the program may open a file and
inadvertently associate it with standard input, standard output, or
standard error.  The program may then read data from or write data to
the file inappropriately.  If the file is one that the user would
normally not have privileges to open, this may result in an
opportunity for privilege escalation.

III. Impact

Local users may gain superuser privileges.  It is known that the
`keyinit' set-user-id program is exploitable using this method.  There
may be other programs that are exploitable.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Standard disclaimer: eu n-am incercat, YMMV.

 Ady (@rofug.ro)
_____________________________________________________________________
| "Be vewy vewy quiet, I'm hunting wuntime ewwors!..." (Elmer Fudd) |

__________________________________________________________
Send 'unsubscribe rofug' to [EMAIL PROTECTED] to unsubscribe

Raspunde prin e-mail lui