[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: 'export RESOLV_HOST_CONF= any file you want' local vulnerability



Andres Salomon wrote:
> 
> Ooops.  Mandrake cooker, and Debian unstable.  In other words: glibc2.2
> systems.  glibc 2.1's resolver (/lib/libnss_db.so.2) appears unaffected.
> This is why some of you aren't seeing it.
> 
> ii  libc6          2.2-6          GNU C Library: Shared libraries and Timezone
> 

Not really, with fping and traceroute suid root it works when logged as root 
and does not when I 'm a regular user. Ping works as usual in both the cases.

Debian 2.2rev2 stable and 

ii  libc6          2.1.3-13       GNU C Library: Shared libraries and Timezone

Mario.



Reply to: