Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Jun 1996 17:37:04 GMT
From:      James Raynard <fqueries@jraynard.demon.co.uk>
To:        robmel@nadt.org.uk
Cc:        questions@freebsd.org
Subject:   Re: CERT advisory -- sperl
Message-ID:  <199606271737.RAA05543@jraynard.demon.co.uk>
In-Reply-To: <199606271006.LAA08676@charlie.nadt.org.uk> (message from Robin Melville on Thu, 27 Jun 1996 11:06:45 %2B0100)

next in thread | previous in thread | raw e-mail | index | archive | help
> A recent CERT advisory warns of vulnerability of "sperl" to attack which
> allows root access to any user on unices which support saved SUID and GUID.
> 
> Is the GNU sperl ported to FreeBSD vulnerable in this way?

Yes. Either FTP down the appropriate file for -current or -stable,
where it's been fixed, or install version 5.003 of Perl.

-- 
James Raynard, Edinburgh, Scotland
james@jraynard.demon.co.uk



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199606271737.RAA05543>