BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Solaris 9/10 ld.so fun Jun 27 2005 11:23PM
Przemyslaw Frasunek (venglin freebsd lublin pl)
Przemyslaw Frasunek wrote:
> ld.so from Solaris 9 and 10 doesn't check LD_AUDIT environment variable when
> running s[ug]id binaries, allowing to run arbitrary code with elevated
> privileges. Well, I can't belive, that such trivial vulnerability exists in
> modern OS...
[...]

Oh, well, it's not th...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus