Re: Vulnerability in dtaction on Digital Unix

1999-09-23 Thread Dave Dittrich
On Thu, 16 Sep 1999, Eric Gatenby wrote: > I just installed this patch and noticed a major omission in the instructions > for the installation of the patch. > > Here are the instructions from the README: > # cd /usr/dt/bin > # cp /patches/dtaction dtaction.new > # chown root:system dtaction.new >

Re: Vulnerability in dtaction on Digital Unix

1999-09-17 Thread Eric Gatenby
I just installed this patch and noticed a major omission in the instructions for the installation of the patch. Here are the instructions from the README: # cd /usr/dt/bin # cp /patches/dtaction dtaction.new # chown root:system dtaction.new # chmod 6555 dtaction.new # ln dtaction dtaction.orig #

Vulnerability in dtaction on Digital Unix

1999-09-16 Thread Zack Hubert
Hello, I have verified that the dtaction vulnerability in CDE can be exploited for local root compromise on Digital Unix systems. Background -- This is a followup to the issue first introduced by Job de Haas on the buffer overflow present within /usr/dt/bin/dtaction. He had verified