看板FB_security
标 题Re: bin/64150: [PATCH] ls(1) coredumps when started via execve(2)
发信站NCTU CSIE FreeBSD Server (Fri Mar 12 11:05:43 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
On Fri, Mar 12, 2004 at 01:06:57PM +0200, Ruslan Ermilov wrote:
> And the fact that optind is initially set to 1. I wonder what
> could be the implications for setuid programs. There could be
> quite unpredictable results, as the "argv" pointer is incorrectly
> advanced in this case, and at least several setuid programs that
> I've glanced at are vulnerable to this attack.
See also:
http://www.freebsd.org/cgi/query-pr.cgi?pr=33738
Marc
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"