Re: [Exim] Linux setuid bug?

Top Page
Delete this message
Reply to this message
Author: Roger Burton West
Date:  
To: exim-users
Subject: Re: [Exim] Linux setuid bug?
On Sat, Jun 10, 2000 at 11:04:21AM +0100, Dirk Koopman wrote:
>Does anyone know whether it is possible to exploit the recent setuid
>'feature' discovered in linux 2.2.* kernels in exim?


There's a disabler for this feature available; it's been posted to
BUGTRAQ (search for "bogus_capset.c", or a message matching:

From: Kyle Sparger <ksparger@???>
Subject:      Re: Sendmail 8.10.2, Linux 2.4.0 - capabilities


), and I'll be happy to pass it on to anyone who wants it. Or, of
course, use kernel 2.2.16.

Roger

--
Actually, we have scientifically determined that Heisenberg did indeed
sleep exactly here. However, we have no idea whatsoever just how fast
asleep he was. -- Dave Aronson