A security hole

brad at bradley.UUCP brad at bradley.UUCP
Fri Mar 11 02:00:00 AEST 1988


Also watch out for "IFS=" in the shell with popen and setuid.  On
system V (not BSD), you can set IFS=/; export IFS and if it does a
popen("/xxx/yuyy", "w"); or "r", then all you need is a a program
called xxx in the current working directory.



More information about the Comp.bugs.sys5 mailing list