BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: 7a69Adv#22 - UNIX unzip keep setuid and setgid files Mar 01 2005 05:57PM
devnull Rodents Montreal QC CA
[As usual when I write here, the header From: is a black hole. Use the
address in the signature to actually reach me.]

>> this only works if the user un-zipping the file is already root.
>> otherwise it creates an "sh" binary which is setuid to the user who
>> unzipped the file.
> If your homedir ...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus