Re: setuid/setgid return values not checked in rlogin, rsh, rshd and uucpd
Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]>
| Newsgroups | gmane.comp.gnu.inetutils.bugs |
|---|---|
| Message-ID | <[email protected]> |
Jeffrey <[email protected]> writes: > I found more occurences of unchecked values for set*id() functions in other > inetutils programs: ftpd, rcp. > > It has different security impact if it can be triggered: > > * rcp: local privilege escalation to the user running the binary > * ftpd: undefined behaviour without privilege escalation as all calls are > to seteuid(0) (gaining root privileges, not dropping it) > > I am attaching a consolidated patch to fix these and the previous ones. Thanks again -- copyright papers have now arrived, and I looked at the patch, and it seems good. However the patch does not apply cleanly due to whitespace and line-wrapping problems, can you re-send the patch as an attachment instead of inline in your email? Please also add NEWS entries (look at earlier entries as templates). /Simon
signature.asc
(application/pgp-signature, 255 B)
-----BEGIN PGP SIGNATURE----- iIoEARYIADIWIQSjzJyHC50xCrrUzy9RcisI/kdFogUCZLuU8RQcc2ltb25Aam9z ZWZzc29uLm9yZwAKCRBRcisI/kdFoqzMAP9hXCH3dvpGHK5YR4USxrl9rHKFkfTR xT8hnGGINjMFlgEA88NKj1Ng216uZ6ejaXS1Ouao3/Z8zW7mmw88lFlUiwA= =EHD3 -----END PGP SIGNATURE-----