ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2000-087.html | vendor advisory |
http://marc.info/?l=bugtraq&m=97249980727834&w=2 | mailing list |
http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html | mailing list |