From owner-doc-jp-work@jp.FreeBSD.org Sat Aug  3 18:17:00 2002
Received: (from daemon@localhost)
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) id g739H0600482;
	Sat, 3 Aug 2002 18:17:00 +0900 (JST)
	(envelope-from owner-doc-jp-work@jp.FreeBSD.org)
Received: from ccm.gs.niigata-u.ac.jp (IDENT:root@ccm.gs.niigata-u.ac.jp [133.35.90.16])
	by castle.jp.FreeBSD.org (8.11.6+3.4W/8.11.3) with ESMTP/inet id g739Gxn00476
	for <doc-jp-work@jp.FreeBSD.org>; Sat, 3 Aug 2002 18:16:59 +0900 (JST)
	(envelope-from si006@ccm.gs.niigata-u.ac.jp)
Received: from localhost.ppp.prin.ne.jp (P061198160233.ppp.prin.ne.jp [61.198.160.233])
	by ccm.gs.niigata-u.ac.jp (8.12.1/8.12.1) with SMTP id g739Gqj0024183
	for <doc-jp-work@jp.FreeBSD.org>; Sat, 3 Aug 2002 18:16:54 +0900
Date: Sat, 03 Aug 2002 18:17:06 +0900
Message-ID: <m27kj8uwrx.wl@ccm.gs.niigata-u.ac.jp>
From: Shun SUZUKI <si006@ccm.gs.niigata-u.ac.jp>
To: doc-jp-work@jp.FreeBSD.org
In-Reply-To: <20020803.031106.02306575.rushani@bl.mmtr.or.jp>
References: <20020803.031106.02306575.rushani@bl.mmtr.or.jp>
User-Agent: Wanderlust/2.9.13 (Unchained Melody) REMI/1.14.3 (Matsudai)
 FLIM/1.14.4 (=?ISO-8859-4?Q?Kashiharajing=FE-mae?=) APEL/10.3 Emacs/20.7
 (powerpc-apple-darwin1.4) MULE/4.0 (HANANOEN)
MIME-Version: 1.0 (generated by REMI 1.14.3 - "Matsudai")
Content-Type: text/plain; charset=ISO-2022-JP
Reply-To: doc-jp-work@jp.FreeBSD.org
Precedence: list
X-Sequence: doc-jp-work 457
Subject: [doc-jp-work 457] Re: ANNOUNCE: FreeBSD Security Advisory FreeBSD-SA-02:32.pppd
Errors-To: owner-doc-jp-work@jp.FreeBSD.org
Sender: owner-doc-jp-work@jp.FreeBSD.org
X-Originator: si006@ccm.gs.niigata-u.ac.jp
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+020727

$BNkLZ!wL5?&$G$9(B

At Sat, 03 Aug 2002 03:11:06 +0900 (JST),
Hideyuki KURASHINA wrote:
> 
> [1  <text/plain; iso-2022-jp (7bit)>]
> $BARIJ$G$9(B.
> 
> 02:32.pppd $B$G$9(B.
> 
> $B!VLdBj$N>\:Y!W$N(B "The call to chmod(2) is subject to a symlink race, ..."
> $B$K<+?.$,$J$$$N$GC!$$$F$/$@$5$$(B.


> A race condition exists in the pppd program that may be exploited
> in order to change the permissions of an arbitrary file.  The file
> specified as the tty device is opened by pppd, and the permissions
> are recorded.  If pppd fails to initialize the tty device in some way
> (such as a failure of tcgetattr(3)), then pppd will then attempt to
> restore the original permissions by calling chmod(2).  The call to
> chmod(2) is subject to a symlink race, so that the permissions may
> `restored' on some other file.
> pppd $B$K$O!"G$0U$N%U%!%$%k$N5v2DB0@-$rJQ99$9$k$?$a$K!"0-MQ2DG=$J(B
> $B6%9g>uBV$,B8:_$7$^$9!#(Bpppd $B$O(B tty $B%G%P%$%9$H$7$F;XDj$7$?%U%!%$%k$r(B
> $B%*!<%W%s$7!"$=$N5v2DB0@-$,5-O?$7$^$9!#$"$kJ}K!(B ($BNc$($P(B tcgetattr(3)
> $B$,<:GT$7$?$H$-$J$I(B) $B$K$h$C$F(B tty $B%G%P%$%9$N=i4|2=$K<:GT$9$k$H!"(Bpppd $B$O(B
> chmod(2) $B$r8F$S=P$7$F%U%!%$%k$NK\Mh$N5v2DB0@-$KLa$=$&$H$7$^$9!#(B
> $B$7$+$7!"(Bchmod(2) $B$O%7%s%\%j%C%/%j%s%/$N6%9g$K=>$&$N$G!"JL$N%U%!%$%k$N(B
> $B5v2DB0@-$r!VJQ99$7$F$7$^$&!W2DG=@-$,$"$j$^$9!#(B

pppd $B$K$O6%9g>uBV$,B8:_$7$F$*$j!"$3$l$r0-MQ$9$k$3$H$G(B
$BG$0U$N%U%!%$%k$N5v2DB0@-$rJQ99$9$k$3$H$,2DG=$G$9!#(B
pppd $B$O(B tty $B%G%P%$%9$H$7$F;XDj$5$l$?(B
$B%U%!%$%k$r%*!<%W%s$9$k:]$K$=$N5v2DB0@-$r5-21$7$F$*$-!"$J$s$i$+$NM}M3(B
($BNc$($P(B tcgetattr(3) 
$B$,<:GT$7$?$H$-$J$I(B) $B$K$h$C$F(Btty $B%G%P%$%9$N=i4|2=$K<:GT$9$k$H!"(Bpppd $B$O(B
chmod(2) $B$r8F$S=P$9$3$H$G%U%!%$%k$NK\Mh$N5v2DB0@-$KLa$=$&$H$7$^$9!#(B
$B$7$+$7!"(Bchmod(2) $B$N8F=P$7$O%7%s%\%j%C%/%j%s%/$N6%9g$K<e$/!"JL$N%U%!%$%k$N(B
$B5v2DB0@-$r!VI|85!W$7$F$7$^$&2DG=@-$,$"$j$^$9!#(B

