Re: smbd remote file creation vulnerability

2001-06-28 Thread sarnold
On Tue, Jun 26, 2001 at 11:08:04AM +0200, Joachim Blaabjerg wrote: > > Appending to /etc/passwd has nothing to do with pam. > > No, not directly, but if your `su` uses PAM to authenticate users and PAM > reacts to the spaces in the beginning of the passwd file, it surely has > something to do wit

Re: SSH allows deletion of other users files...

2001-06-05 Thread sarnold
On Mon, Jun 04, 2001 at 11:19:37AM -0400, David F. Skoll wrote: > I could not duplicate this with OpenSSH 2.9p1-1 on Red Hat 6.2 David (and other bugtraq readers), we think we have found some additional information that is important in tracking the source of the problem. The problem code is invo