Bug 20111
Summary: | RH6.2 dump SUID exploit (via RSH env. var) | ||
---|---|---|---|
Product: | [Retired] Red Hat Linux | Reporter: | Philip Rowlands <bugzilla> |
Component: | dump | Assignee: | Nalin Dahyabhai <nalin> |
Status: | CLOSED ERRATA | QA Contact: | Dale Lovelace <dale> |
Severity: | medium | Docs Contact: | |
Priority: | high | ||
Version: | 6.2 | CC: | dr |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2000-11-03 03:08:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Philip Rowlands
2000-10-31 17:52:26 UTC
Advise for anyone who needs a quick fix: either remove the package, if you don't need it (rpm -e dump), or remove the SUID bit from /sbin/dump *and* /sbin/restore (restore(8) lists the same RSH variable). *** Bug 20112 has been marked as a duplicate of this bug. *** Fixed in dump-0.4b19-5. dump-static suffers obviously from the same problem, so an errata update is needed for this package, too. Reopening. The advisory mentiones update RPMs for dump-static and rmt, but they are not on updates.redhat.com. 19:48:40 `SRPMS/dump-0.4b19-5.6x.src.rpm' size = 166647 has new time, getting 19:48:41 `i386/dump-0.4b19-5.6x.i386.rpm' size = 88538 has new time, getting 19:48:41 `i386/dump-static-0.4b19-5.6x.i386.rpm' size = 426967 is missing, getting. 19:48:41 `i386/rmt-0.4b19-5.6x.i386.rpm' size = 12550 is missing, getting. ok, so the dump errata was re-issued, now with dump-static & rmt. Closing bug. |