Re: IRIX 5.2 Security Advisory - Mystery Solved

Martin Hargreaves (mjh25920@ggr.co.uk)
Wed, 10 Aug 1994 15:02:48 +0000 (GMT)

On Wed, 10 Aug 1994, Jim Littlefield wrote:
 
> The only time the hole can be exploited is when sgihelp is running as root.
> Clogin runs as root, of course. It may be possible to do the same thing via the
> "System Manager" functions, although I have not checked (yet).

	/usr/sbin/PrintStatus runs suid root, and calls sgihelp. F1 isn't 
needed you can just hit the help button.

	Martin.


 Martin Hargreaves       |  mjh25920@ggr.co.uk 
 Computational Chemist   |  ch11mh@surrey.ac.uk
 Glaxo  R & D 		 |  No problem is so large that 
 & Surrey University	 |  we can't fit it in somewhere