Re: perl suid exploit

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, Jul 08, 2005 at 01:55:26PM +1000, Michael Mansour wrote:
> I run perl 5.8.3 in suid mode on Fedora Core 1, and
> have recently detected an attempted exploit which
> basically crashed my system (well, I was able to
> recover by removing the 15 byte /etc/ld.so.preload
> file which tries to reference, as part of the exploit,
> a /tmp/getuid.so file).
> 
> I've brought the server up again, but am not sure now
> how I can defend against this attack since FC1 and
> perl 5.8.3 are the latest.
> 
> Anyone have any suggestions?


Well.... <https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152845>


-- 
Matthew Miller           mattdm@xxxxxxxxxx        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>
Current office temperature: 76 degrees Fahrenheit.

--

fedora-legacy-list@xxxxxxxxxx
http://www.redhat.com/mailman/listinfo/fedora-legacy-list

[Index of Archives]     [Fedora Development]     [Fedora Announce]     [Fedora Legacy Announce]     [Fedora Config]     [PAM]     [Fedora General Discussion]     [Big List of Linux Books]     [Gimp]     [Yosemite Questions]

  Powered by Linux