Re: odd chown difference between 2.0 and 2.1pre kernels

Raul Miller (rdm@test.legislate.com)
Wed, 13 Jan 1999 12:31:02 -0500


On Tue, 12 Jan 1999, Raul Miller wrote:
> > > > Race condition if you can figure out what root is doing -- just setuid
> > > > between time root examines files and chown.

David C Niemi <niemi@tux.org> wrote:
> That race condition still exists in Linux 2.0.x. So if you are vulnerable
> to this attack in 2.2 you are also vulnerable in 2.0.x, it just may be a
> little harder to exploit.

How so?

Under 2.0, chown root cleared setuid.

-- 
Raul

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/