Re: CERT Advisory CA-93:17

John Hawkinson (jhawk@panix.com)
Wed, 17 Nov 1993 18:38:57 -0500 (EST)

Dave Goldberg writes:
> Is this a new bug in XR5?  It doesn't seem to show up on a couple of
> machines here that run a vendor's XR4 (mips RISCwindows in
> particular).

It's my understanding that it applies to R4 as well.

It should be remembered that this only applies to installations of
xterm that are setuid/setgid. Some vendors, such as Sun, do
not distribute xterm setuid or setgid, so those systems are safe.

--
John Hawkinson
jhawk@panix.com