Bug 16738 - suid minicom to uucp
Summary: suid minicom to uucp
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: minicom
Version: 7.1
Hardware: i386
OS: Linux
Target Milestone: ---
Assignee: Bill Nottingham
QA Contact:
Keywords: Security
: 16853 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2000-08-22 19:04 UTC by Arenas Belon, Carlo Marcelo
Modified: 2014-03-17 02:16 UTC (History)
1 user (show)

Clone Of:
Last Closed: 2000-08-24 23:32:07 UTC

Attachments (Terms of Use)

Description Arenas Belon, Carlo Marcelo 2000-08-22 19:04:30 UTC
from bugtraq, tested on RC1

> [lcamtuf@nimue lcamtuf]$ minicom -C foo
> minicom: there is no global configuration file /etc/minirc.dfl
> Ask your sysadm to create one (with minicom -s).
> [lcamtuf@nimue lcamtuf]$ ls -l foo
> -rw-rw-r--   1 lcamtuf  uucp            0 Aug 18 12:21 foo
>     ^^                  ^^^^
> Any file can be created anywhere with uucp privledges - it will follow
> symlinks. Not nice on systems running uucp services.

Comment 1 Bill Nottingham 2000-08-22 19:40:11 UTC
Yes. The 'anywhere' is misleading; it can only create files
in places group-writable by uucp.

Comment 2 Bill Nottingham 2000-08-24 23:32:05 UTC
*** Bug 16853 has been marked as a duplicate of this bug. ***

Comment 3 Bill Nottingham 2000-08-24 23:32:20 UTC
Should be fixed in minicom-1.83.1-4.

Note You need to log in before you can comment on or make changes to this bug.