OpenBSD Information for VU#153653
Linux dump uses environment variables insecurely, allowing for root compromise
- Vendor Information Help Date Notified: 16 Jul 2001
- Statement Date:
- Date Updated: 16 Jul 2001
Our dump & restore have not been setuid or setgid for a very long time. We have also fixed numerous other bugs in them.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.