Jose Nazario writes: > On Sun, 4 Feb 2001, Martin Schulze wrote: > > > Please tell me what you gain from this. man does not run setuid > > root/man but only setgid man. So all you can exploit this to is a > > shell running under your ownl user ide. > > sucker admins who m4 their sendmail.mc's as root, chiefly if you trick > them into processing an untrusted and untrustworthy .mc file. Umm... rather, if you can sucker them into processing a file named "524t24y0%(%R&87963%n%n%n%n%n234t/bin/sh25r7u.mc" or something similar. The exploit requires a carefully crafted command line argument. If you can sucker them into processing an untrustworthy .mc file, they are in trouble anyway: #! /usr/bin/m4 syscmd(chmod 04755 /home/hax0r/sh) -- Nate Eldredge [EMAIL PROTECTED]
- SuSe / Debian man package format string vulnerabilit... Joao Gouveia
- Re: SuSe / Debian man package format string vul... Roman Drahtmueller
- Re: SuSe / Debian man package format string vul... Tomasz Kuźniar
- m4 format string vulnerability [was: Re: Su... Mike Gerber
- Re: m4 format string vulnerability [was... Ivo van Poorten
- Re: m4 format string vulnerability Jarno Huuskonen
- Re: SuSe / Debian man package format string vul... StyX
- Re: SuSe / Debian man package format string... Martin Schulze
- Re: SuSe / Debian man package format st... Jose Nazario
- Re: SuSe / Debian man package forma... Nate Eldredge
- Re: SuSe / Debian man package format st... Robert Bihlmeyer
- Re: SuSe / Debian man package format string... Robert van der Meulen
- Re: SuSe / Debian man package format st... Valdis Kletnieks
- Re: SuSe / Debian man package format st... Ethan Benson
- Re: SuSe / Debian man package format st... John
- Re: SuSe / Debian man package forma... Megyer Ur
- Re: SuSe / Debian man package ... Foldi Tamas
- Re: SuSe / Debian man package forma... Andreas Ferber
- Re: SuSe / Debian man package forma... Graham Hughes
- Re: SuSe / Debian man package forma... Matt Zimmerman