Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Lack of environment sanitization in the FreeBSD, OpenBSD, NetBSD dynamic loaders. Nov 22 2006 09:02PM
In Cognito (defend the world gmail com)
Impact: Serious. May lead to privilege escalation.

A class of security vulnerabilities has resurfaced in the dynamic loaders
of FreeBSD, OpenBSD, and NetBSD in the sanitization of environment
variables for suid and sgid binaries.

Due to either badly implemented sanitization or a lack of it, a set...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus