Date: Mon, 13 Oct 2008 16:17:16 +0200 From: Tomas Hoger <thoger@...hat.com> To: oss-security@...ts.openwall.com Cc: coley@...re.org Subject: Re: CVE Request On Fri, 10 Oct 2008 14:06:38 -0400 (EDT) Josh Bressers <bressers@...hat.com> wrote: > fence: http://bugs.gentoo.org/show_bug.cgi?id=240576 Please mention both fence_apc and fence_apc_snmp in the CVE description, as both agents do the same kind of logging. Description may also mention cman package, as those fencing agents may be bundled in fence or cman package, based on the version used. Note: CVE-2008-4192 was recently assigned to fence_egenera having similar flaw. Additionally, fence_manual / fence_ack_manual communicate via FIFO socket created in /tmp. fence_manual creates fifo /tmp/fence_manual.fifo and waits for fence_ack_manual to write to it. This can possibly result in the overwrite of arbitrary file. -- Tomas Hoger / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ