5 lines
No EOL
406 B
Text
5 lines
No EOL
406 B
Text
source: https://www.securityfocus.com/bid/472/info
|
|
|
|
The xfsdump program shipped with Irix 5.x and 6.x from SGI contains a vulnerability which could lead to root compromise. By creating a log file in /usr/tmp called bck.log, a user could create a symbolic link from this file to any file they wish to be created as root. This is turn could be used to compromise the system.
|
|
|
|
ln -sf /.rhosts /usr/tmp/bck.log |