Re: 011: SECURITY FIX: February 12, 2006
Darren Tucker <[email protected]>
| Newsgroups | gmane.os.openbsd.www |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Feb 16, 2006 at 05:35:53AM -0500, Wayne Facer wrote:
> I'd like to get some additional information about this patch that was
> issued for OpenBSD 3.7. Specifically can this exploit be remotely
> exploited or is it something that's local to the machine?
The only attack vector I'm aware of is if an attacker can create arbitrary
files which a victim later attempts to scp, they can cause the victim
to execute a command of the attacker's chosing.
If the attacker can't create files, or induce a victim to copy those
files then they can't gain anything.
--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.