[comp.unix.sysv386] More security bugs

eric@mks.com (Eric Gisin) (02/26/91)

I found another security bug.
This one is only in Interactive UNIX 2.2,
and lets you make /bin and /etc writable.

I'm not going to post details, but instead call on Interactive
and all other System V/386 vendors to post to this newsgroup
instructions for reporting serious bugs, and a promise that
serious bugs reports will be acknowledged.

I have reported other serious bugs (cause crashes) to Interactive.
We don't have any support contract, but they did not even acknowledge
that they received the bug reports.

	Eric Gisin, Mortice Kern Systems, <eric@mks.com>

support@bomber.ism.isc.com (Support Account) (02/27/91)

In article <1991Feb25.204607.13455@mks.com> eric@mks.com (Eric Gisin) writes:
>I'm not going to post details, but instead call on Interactive
>and all other System V/386 vendors to post to this newsgroup
>instructions for reporting serious bugs, and a promise that
>serious bugs reports will be acknowledged.

Any bugs or problems, serious or trivial, can be reported to:

support@ism.isc.com

All mail to this alias has been and will continue to be
acknowledged.

>I have reported other serious bugs (cause crashes) to Interactive.
>We don't have any support contract, but they did not even acknowledge
>that they received the bug reports.

We apologize for not acknowledging your reports, but can't find
any mail from you that should have been acknowledged. Please
resend to the above account.

With any bug reports, it obviously helps to have as much
information as possible to duplicate or approximate the environment
and problem. Please provide hardware and software configurations,
serial number of the operating system, and test programs, if
applicable.

Interactive Systems Corporation Support

jdeitch@jadpc.cts.com (Jim Deitch) (03/02/91)

>Any bugs or problems, serious or trivial, can be reported to:
>
>support@ism.isc.com
>
>All mail to this alias has been and will continue to be
>acknowledged.
>
..... (more on this account deleted)

>
>Interactive Systems Corporation Support

Is this new?  I tried to send mail to this account about 2-3 months
ago and it bounced, saying that user was unknown?  If you want I can
probably dig up the headers.

Jim
-- 
ARPANET:    jadpc!jdeitch@nosc.mil
INTERNET:   jdeitch@jadpc.cts.com
UUCP:	    nosc!jadpc!jdeitch

support@bomber.ism.isc.com (Support Account) (03/05/91)

In article <1991Mar02.031353.12053@jadpc.cts.com> jdeitch@jadpc.cts.com (Jim Deitch) writes:
>>Any bugs or problems, serious or trivial, can be reported to:
>>support@ism.isc.com
>Is this new?  I tried to send mail to this account about 2-3 months
>ago and it bounced, saying that user was unknown?  If you want I can
>probably dig up the headers.
>

Try it now. The account is not new, but there have been
intermittent problems with mail paths and gateways.







Interactive Systems Corporation Support
>