Subject: Re: Bugtraq: procfs hole
To: Michael Graff <explorer@flame.org>
From: Jason Thorpe <thorpej@nas.nasa.gov>
List: tech-security
Date: 08/12/1997 05:57:48
On 12 Aug 1997 07:21:19 -0400 
 Michael Graff <explorer@flame.org> wrote:

 > Now, you have a read/write fd open to a setuid processes's program space.
 > This is bad.
 > 
 > Can someone forward the FreeBSD fix for this?  I'll look at it and see if
 > I feel comfortable committing it.  If I don't, I'd still like to have
 > the patch asap :)

I've looked at it... it's semi-reasonable.. there need to be a few changes,
but it seemed to be almost the right thing... with a minor change, it gives
you almost ptrace(2) semantics.

Jason R. Thorpe                                       thorpej@nas.nasa.gov
NASA Ames Research Center                            Home: +1 408 866 1912
NAS: M/S 258-6                                       Work: +1 415 604 0935
Moffett Field, CA 94035                             Pager: +1 415 428 6939