[Cooker] KDE: /usr/bin/kdesud, gid = 0 exploit (fwd)

2000-05-28 Thread Frank Meurer
FYI -- Forwarded message -- Date: Fri, 26 May 2000 19:21:10 +0300 From: noir [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: KDE: /usr/bin/kdesud, gid = 0 exploit /usr/bin/kdesud has DISPLAY enviroment variable overflow. tested on Mandrake 7.02 (Air), exploit will get you

Re: [Cooker] KDE: /usr/bin/kdesud, gid = 0 exploit (fwd)

2000-05-28 Thread Chmouel Boudjnah
Frank Meurer [EMAIL PROTECTED] writes: FYI Fix already posted, security package update come in few minutes. /usr/bin/kdesud has DISPLAY enviroment variable overflow. tested on Mandrake 7.02 (Air), exploit will get you gid=0 Shameless self promotion: Any security related job in