Vulnerability Development mailing list archives

Re: Pine, Pico, Pilot Program Overflow bug.


From: "Larry W. Cashdollar" <lwc () vapid dhs org>
Date: Wed, 28 Nov 2001 15:13:48 -0500 (EST)



That can't be right.  Its not on any of my boxes, and if it were it would
be a gaping security hole.

On Wed, 28 Nov 2001, Jay D. Dyson wrote:

-----BEGIN PGP SIGNED MESSAGE-----

On Wed, 28 Nov 2001, uexploit xeightwo wrote:


      Is the pico binary typically distro'd as suid root as is listed in
the above document?  I can't imagine why it would need to be.  Seems like
a recipe for disaster.



Current thread: