[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: misc/screen local root compromise



David Krause (openbsd_(_at_)_davidkrause_(_dot_)_com) wrote:
> http://www.linuxsecurity.com/advisories/suse_advisory-1594.html

> The screen authors didn't update the ChangeLog for 3.9.10, but
> apparently there is a local root compromise.  Isn't that nice that
> they didn't seem to notify us.  I saw the SuSE vulnerability above
> and it mentioned it.  I haven't seen this on bugtraq yet or from any
> of the other vendors.  The vulnerability only occurs if screen is
> installed setuid root.

http://www.acm.uiuc.edu/workshops/security/setuid.html

Any good reason for screen to be suid?


Cya, Han.



Visit your host, monkey.org