Date: Вт, 30 ноя 1999 05:50:39
От: UNYUN <shadowpenguin@BACKSECTION.NET>
Кому: BUGTRAQ@SECURITYFOCUS.COM
Тема: another hole of Solaris7 kcms_configure
--------------------------------------------------------------------------------
Hello
kcms_configure has a overflow bug with "-P" option and it has been
reported(107339-01). But, this program has another hole.
kcms_configure overflows if long string is specified in NETPATH
environment, it is exploitable. I coded an exploit for Solaris7 intel
edition to obtain a root privilege.
------ ex_kcms_configure86.c
/*=============================================================================
kcms_configure Exploit for Solaris7 Intel Edition
The Shadow Penguin Security (http://shadowpenguin.backsection.net)
Written by UNYUN (shadowpenguin@backsection.net)
=============================================================================
*/