Re: 011: SECURITY FIX: February 12, 2006

Darren Tucker <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <[email protected]>
On Thu, Feb 16, 2006 at 05:35:53AM -0500, Wayne Facer wrote:
> I'd like to get some additional information about this patch that was 
> issued for OpenBSD 3.7.  Specifically can this exploit be remotely 
> exploited or is it something that's local to the machine? 

The only attack vector I'm aware of is if an attacker can create arbitrary
files which a victim later attempts to scp, they can cause the victim
to execute a command of the attacker's chosing.

If the attacker can't create files, or induce a victim to copy those
files then they can't gain anything.

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.