Slashdot Mirror


Solaris, AIX Login Hole

An anonymous submitter sent in: "A CERT Advisory describes a buffer overflow vulnerability in implementations of login derived from System V, which includes among Solaris 8 and earlier and AIX 4.3/5.1. "An exploit exists and may be circulating." Vendors are testing fixes." There's a Reuters story as well.

7 of 267 comments (clear)

  1. Let me guess... by wiredog · · Score: 5, Funny

    You can login as kt and get root.

  2. The FBI is disappointed. . . by Slicebo · · Score: 5, Funny

    I guess that fixing this issue will delay delivery of "Magic Lantern for Unix" for a few months.

    1. Re:The FBI is disappointed. . . by jd · · Score: 4, Funny

      Shhhhhhhhhhh! The FBI still thinks that Windows is the only OS out there, and that Bill Gates invented the Internet!

      --
      It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
    2. Re:The FBI is disappointed. . . by CoolVibe · · Score: 3, Funny
      *SLAP* no, Al Gore invented the internet, not Bill Gates... sheesh...

      :-)

  3. 'Another Gaping security hole goes unpatched?' by Anonymous Coward · · Score: 3, Funny

    Isn't this where Michael says:
    'Another gaping security hole goes unpatched by Microsoft... Uh, I mean, er, Sun' ?

  4. Re:Another argument for open source by gilroy · · Score: 3, Funny
    Blockquoth the poster:

    It's an unchecked buffer, for God's sake. Most C coders can fix a problem like this in their sleep.


    ... which is good, since that's apparently where they're coding, too. :)
  5. ...have already won by Anonymous Coward · · Score: 1, Funny

    If we can't use Telnet, then the terrorists have already won!