Home » Hacking News » OpenBSD 3.0: Bug in rshd(8) and rexecd(8)

OpenBSD 3.0: Bug in rshd(8) and rexecd(8)

by Nikola Strahija on April 12th, 2002 Under certain conditions, on systems using YP with netgroups in the password database, it is possible for the rshd(8) and rexecd(8) daemons to execute the shell from a different user's password entry. Due to a similar problem, atrun(8) may change to the wrong home directory when running at(1) jobs.

This only affects OpenBSD 3.0, prior versions are not affected.

Patch is available.

