[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freebsd-security
Subject:    Re: Security breach or VM flaw? (security check output)
From:       Eivind Eklund <eivind () FreeBSD ! ORG>
Date:       1999-01-28 11:00:26
[Download RAW message or body]

On Thu, Jan 28, 1999 at 12:17:30AM +0100, laurens van alphen wrote:
> Hiya folks,
> 
> This mornin' i received this daily security check output:
> (of course, hostnames have been changes, dates/sizes have not)
> 
> <host> setuid diffs:
> 40c40
> < -r-xr-s---  1 bin   kmem  49152 Jul 22 10:14:47 1998 /usr/bin/netstat
> ---
> > -r-xr-s---  1 bin   kmem  49152 Jan 28 02:30:23 1999 /usr/bin/netstat
> 
> Is seems as if netstat has adopted the time at which it was executed.

That's exactly what has happened.  It was a bug in the VM system,
where read only pages sometimes (very seldom) were marked as dirty.  I
think it has been fixed in 2.2.8+.

Eivind.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic