Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Jun 1996 09:14:12 +0200 (MET DST)
From:      guido@gvr.win.tue.nl (Guido van Rooij)
To:        scanner@orion.webspan.net (Scanner)
Cc:        taob@io.org, freebsd-security@freebsd.org
Subject:   Re: CERT Advisory CA-96.12 - Vulnerability in suidperl (fwd)
Message-ID:  <199606270714.JAA25584@gvr.win.tue.nl>
In-Reply-To: <Pine.BSI.3.93.960626184038.13501G-100000@orion.webspan.net> from Scanner at "Jun 26, 96 06:40:56 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
Scanner wrote:
> On Thu, 27 Jun 1996, Guido van Rooij wrote:
> 
> > Brian Tao wrote:
> > [There is text before PGP section.]
> > >     I believe this applies to perl4 as shipped with all versions of
> > > FreeBSD, as well as the perl5 packages/ports.  Does anyone know what
> > > the actual vulnerability is?
> > 
> > We know. This bug was first reported by Paul Traina to CERT.
> > Of course we're not going to get into details.
> Ok sure fine take all the fun out of it. :-)
> 

The fun is not reading how it is done, but finding it ;-)

-Guido



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199606270714.JAA25584>