Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 8 Feb 2001 11:07:36 +0100
From:      Rahul Siddharthan <rsidd@physics.iisc.ernet.in>
To:        Brett Glass <brett@lariat.org>
Cc:        Paul Richards <paul@originative.co.uk>, chat@FreeBSD.ORG
Subject:   Re: Laugh: [Fwd: Microsoft Security Bulletin MS01-008]
Message-ID:  <20010208110736.F2429@lpt.ens.fr>
In-Reply-To: <4.3.2.7.2.20010207233106.0458f7c0@localhost>; from brett@lariat.org on Wed, Feb 07, 2001 at 11:32:02PM -0700
References:  <3A81DDC9.EF6D7D84@originative.co.uk> <4.3.2.7.2.20010207233106.0458f7c0@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
Brett Glass said on Feb  7, 2001 at 23:32:02:
> At 04:44 PM 2/7/2001, Paul Richards wrote:
> 
> >You've gotta laugh really, a root compromise exists and the mitigating
> >controls are to not let anyone use the box!
> 
> What's the difference between this and the recent procfs local root
> exploit in FreeBSD?

Maybe this: that the FreeBSD advisory doesn't consider it a 
"mitigating control" that only local users with permission to
run arbitrary programs can exploit it, or claim that
"best practices recommend against this"?

R


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-chat" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010208110736.F2429>