Date: Sat, 28 Feb 1998 17:32:21 +0100 From: viinikala Subject: x11amp playlist bug hi, x11 audio mpeg player (x11amp) version 0.65, when installed setuid root (as suggested by the README file), creates playlist files in ~/.x11amp while making 'root' the owner of these plaintext files (instead of the proper user). unfortunatelly, the program DOES follow symlinks, and overwriting for instance /etc/shadow is therefore trivial: mkdir ~/.x11amp ln -s /etc/shadow ~/.x11amp/ekl now run x11amp, get into the playlist menu, select 'ekl', mark all the entries and hit 'delete'. no matter if the prg crashes (it might), /etc/shadow is gone, anyway. viinikala/rvl&grif ----------------------------------------------------------------------------- Date: Sun, 1 Mar 1998 13:00:33 -0500 From: Jeff Johnson Subject: x11amp bug you can also read files not owned by you, but I have not found a way to display them yet. But, if another user has a lot of mp3 files, fire up x11amp and you'll be able to play them. also, start x11amp with a VERY VERY VERY LONG filename and it seg faults.... buffer overflow? -- trn@flinet.com - [LwZ] - http://www.flinet.com/~trn I poured Spot remover on my dog. Now he's gone. *sniff* ----------------------------------------------------------------------------- Date: Sun, 1 Mar 1998 19:31:14 +0100 From: root Subject: Re: x11amp bug The symlink bug are fixed! get it at http://www.x11amp.ml.org Crocodile - x11amp staff