Mailing List Archive

Support open source code!


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Compiling kterm



On Wed, Jun 20, 2001 at 11:36:08PM -0400, Josh Glover wrote:
> Quoting Christopher SEKIYA <wileyc@example.com>:
> 
> > Consider using rxvt instead.  kterm is horribly
> > broken.
> 
> Anybody using rxvt should be aware of some security bug
> (root exploit, if I remember correctly). I don't remember
> the details, but if you head over to www.securityfocus.com
> and search the BugTraq archives, you should find a dozen
> posts or so on the vulnerability.

It's a root exploit only if rxvt has root privileges, i.e. setuid root.
I hope nobody was *that* stupid in this day and age. (It looks like some
distributions did install rxvt as setgid utmp.) 

-- 
Shimpei Yamashita                               http://www.shimpei.org/


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links