security bug in ISC sysv386. here's a quick fix.

Karl Denninger kdenning at pcserver2.naitc.com
Sat Feb 16 03:59:08 AEST 1991


In article <1991Feb13.132436.3507 at chinet.chi.il.us> randy at chinet.chi.il.us (Randy Suess) writes:
>In article <1991Feb12.200752.2772 at vort.uucp> mike at vort.uucp (Mike Nemeth) writes:
>>calm down folks, there's a quick fix. if you're root just do the following:
>]# cd /
>]# /etc/conf/bin/idtune UAREARW 0
>
>	That only works if you have a math coprocessor.  I have an idea
>	that the majority of ISC systems don't have them, and many are
>	public access systems.
>-- 
>Randy Suess
>randy at chinet.chi.il.us

The cost of entry for an ISC person just went up about $500.  No math chip,
no way to work around the bug.

Thanks ISC.

--
Karl Denninger - AC Nielsen, Bannockburn IL (708) 317-3285
kdenning at nis.naitc.com

"The most dangerous command on any computer is the carriage return."
Disclaimer:  The opinions here are solely mine and may or may not reflect
  	     those of the company.



More information about the Comp.unix.sysv386 mailing list