[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAF9MOy7yuinFXcXWeUJOAiw+t7UKfOWfDNzQVOoybWLDe1_nag@mail.gmail.com>
Date: Wed, 14 Mar 2012 15:10:36 +1030
From: Frankie Cutlass <frankiecutlass12@...il.com>
To: paul.szabo@...ney.edu.au
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: [iputils] Integer overflow in iputils
ping/ping6 tools
Incorrect. Ping is setuid root but it drops privs before reaching this
code path. Even if you could exploit that for root (you cant) all you
would end up with is a shell as your uid and a raw socket..
>Fork bombs do not run privileged, but /bin/ping is setuid root.
>
>Cheers, Paul
>
>Paul Szabo psz () maths usyd edu au http://www.maths.usyd.edu.au/u/psz/
>School of Mathematics and Statistics University of Sydney Australia
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists