BugTraq
MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability Dec 07 2004 02:36AM
Mandrake Linux Security Team (security linux-mandrake com) (1 replies)
Re: MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability Dec 08 2004 04:44AM
David F. Skoll (dfs roaringpenguin com)
On Mon, 7 Dec 2004, Mandrake Linux Security Team wrote:

> Max Vozeler discovered a vulnerability in pppoe, part of the rp-pppoe
> package. When pppoe is running setuid root, an attacker can overwrite
> any file on the system.

As the author of rp-pppoe, I take exception to this being reported as
a "vulnerability". pppoe is NOT designed to run setuid-root. You may
as well claim that a setuid "cat" has a vulnerability that lets it read
arbitrary files.

Any Linux distro that installs pppoe setuid root is just plain dangerous.

--
David.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus