[<prev] [next>] [day] [month] [year] [list]
Message-Id: <76F33288-7011-4EB9-80D5-98CDD8926A4A@propagandaprod.com>
Date: Wed, 23 Aug 2006 11:04:21 +0200
From: Propaganda Support <support@...pagandaprod.com>
To: full-disclosure@...ts.grok.org.uk
Subject: NETRAGARD-20060624 SECURITY ADVISORY] [ROXIO
TOAST 7 TITANIUM - LOCAL ROOT COMPROMISE ]
Alex wrote:
> Making system() calls without a full path from a suid root binary
> is just asking for trouble.
Agreed. No argument.
> You should fix it.
I neglected to mention that I have. It will be released shortly.
Kind Regards,
-jeff
--
Jeff Holland
http://propagandaprod.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists