Date: Ср, 15 сен 1999 03:06:27
От: Brock Tellier <btellier@WEBLEY.COM>
Кому: BUGTRAQ@SECURITYFOCUS.COM
Тема: SCO 5.0.5 lpr local root exploit
--------------------------------------------------------------------------------
Greetings,
There is a hole in SCO 5.0.5, probably 5.0.x, /usr/bin/lpr. Or more
accurately, /usr/lpd/remote/lp, which lpr execs and passes your command
line args on to. This means that while /usr/bin/lpr is sgid lp, we'll
still get a rootshell because /usr/lpd/remote/lp is suid root/sgid
daemon. I haven't looked into the remote angle of this exploit, though
the pathname is hardly encouraging.
FIX: I would recommend a recursive directory sbit-search-and-destroy if
you're running SCO..