[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SECURITY PROBLEM: autofs [all versions]

On Fri, Jun 30, 2000 at 08:52:23PM -0400, Christopher W. Curtis wrote:
> [...] filed a bug report against autofs
> and marked it as release critical.  I have heard nothing for the past
> two (three?) days and need to make this known: [...]

The bug tracking system has been playing up over the last couple of days,
it should be fixed now.

> [sneakernet to victim]


[sneakernet to victim]
hit reset button, or toggle power switch
put bootable disk in drive
boot into minimal OS
mount various partitions
edit /etc/passwd

Giving console access to people you don't trust isn't a good idea with
or without bugs in autofs.


Anthony Towns <aj@humbug.org.au> <http://azure.humbug.org.au/~aj/>
I don't speak for anyone save myself. GPG signed mail preferred.

  ``We reject: kings, presidents, and voting.
                 We believe in: rough consensus and working code.''
                                      -- Dave Clark

Attachment: pgpIdCzDpFlrI.pgp
Description: PGP signature

Reply to: