BugTraq
Re: [Full-disclosure] Solaris 9/10 ld.so fun Jun 28 2005 05:48PM
Piotr KUCHARSKI (chopin sgh waw pl) (1 replies)
On Tue, Jun 28, 2005 at 06:17:02PM +0200, Przemyslaw Frasunek wrote:
> This vulnerability was introduced by one of the recent patches for Solaris 9,
> possibly 112963. Ld.so patched with 112963-08 is not vulnerable -- it does
> not allow LD_AUDIT for set[ug]id binaries, but upgrading to 112963-16
> definitly makes ld.so exploitable.

Just patchrm-ed 112963-19 to -12, it is not working anymore.

p.

--
Beware of he who would deny you access to information, for in his
heart he dreams himself your master. -- Commissioner Pravin Lal
http://nerdquiz.sgh.waw.pl/ -- polska wersja quizu dla nerdów ;)

[ reply ]
RE: [Full-disclosure] Solaris 9/10 ld.so fun Jun 29 2005 12:04AM
Charles Heselton (charles heselton gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus