Re: BUGTRAQ ALERT: Solaris 2.x vulnerability

David Rukshin (rukshin@caip.rutgers.edu)
Fri, 18 Aug 1995 08:42:54 BST

: Just to add my two cents to the discussion:
:        - it is fixed in 2.5 (by using fchown, not chown, both versions of ps)

I was able to reproduce the problem on a SPARC 5/85 running Solaris 2.5 BETA
within approximately 2.5 minutes when using /usr/bin/ps
I was not very successful in doing so with /usr/ucb/ps.  But then again, may
be I haven't let the job run long enough.

Dave

__________________________________________________________________________
David Rukshin                                   <rukshin@caip.rutgers.edu>
Student Systems Programmer                      {...}!rutgers!caip!rukshin
CAIP Center, Rutgers University                 614 CoRE Blng 908/445-5553