Bug 16738 - suid minicom to uucp
suid minicom to uucp
Status: CLOSED CURRENTRELEASE
Product: Red Hat Linux
Classification: Retired
Component: minicom (Show other bugs)
7.1
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Bill Nottingham
: Security
: 16853 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2000-08-22 15:04 EDT by Arenas Belon, Carlo Marcelo
Modified: 2014-03-16 22:16 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-08-24 19:32:07 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Arenas Belon, Carlo Marcelo 2000-08-22 15:04:30 EDT
from bugtraq, tested on RC1

> [lcamtuf@nimue lcamtuf]$ minicom -C foo
> minicom: there is no global configuration file /etc/minirc.dfl
> Ask your sysadm to create one (with minicom -s).
>
> [lcamtuf@nimue lcamtuf]$ ls -l foo
> -rw-rw-r--   1 lcamtuf  uucp            0 Aug 18 12:21 foo
>     ^^                  ^^^^
>
> Any file can be created anywhere with uucp privledges - it will follow
> symlinks. Not nice on systems running uucp services.
Comment 1 Bill Nottingham 2000-08-22 15:40:11 EDT
Yes. The 'anywhere' is misleading; it can only create files
in places group-writable by uucp.
Comment 2 Bill Nottingham 2000-08-24 19:32:05 EDT
*** Bug 16853 has been marked as a duplicate of this bug. ***
Comment 3 Bill Nottingham 2000-08-24 19:32:20 EDT
Should be fixed in minicom-1.83.1-4.

Note You need to log in before you can comment on or make changes to this bug.