solaris 9/10 ld.so local root shell bug# Security - 系统安全
T*r
1 楼
ate: Tue, 28 Jun 2005 01:11:58 +0200
From: Przemyslaw Frasunek
To: f*************[email protected], b*****[email protected]
Subject: Solaris 9/10 ld.so fun
[ The following text is in the "ISO-8859-2" character set. ]
[ Your display is set for the "hz-gb-2312" character set. ]
[ Some characters may be displayed incorrectly. ]
ld.so from Solaris 9 and 10 doesn't check LD_AUDIT environment variable when
running s[ug]id binaries, allowing to run arbitrary
From: Przemyslaw Frasunek
To: f*************[email protected], b*****[email protected]
Subject: Solaris 9/10 ld.so fun
[ The following text is in the "ISO-8859-2" character set. ]
[ Your display is set for the "hz-gb-2312" character set. ]
[ Some characters may be displayed incorrectly. ]
ld.so from Solaris 9 and 10 doesn't check LD_AUDIT environment variable when
running s[ug]id binaries, allowing to run arbitrary