TUCoPS :: HP/UX :: bt107.txt

HP-UX 11.0 /usr/lbin/rwrite


There is a vulnerability in /usr/lbin/rwrite on HP-UX 11.0 (other versions might be vulnerable too).

/usr/lbin/rwrite is installed setuid to root by default.

$ /usr/lbin/rwrite something `perl -e 'print "A" x 14628'` something
Segmentation fault

Solution : remove setuid bit until patch is available.

Tried to contact , got "Client rejected. Access denied".

