Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 09 Nov 2009 22:09:41 +0100
From: Florian Weimer <fw@...eb.enyo.de>
To: oss-security@...ts.openwall.com
Subject: Re: X server umask issue

* Josh Bressers:

> What I am wondering though, are there other files the X server creates that could
> be an issue for this? I'm not aware of any, but I'm also not an expert by any
> stretch of the imagination. Am I missing something else?

Doesn't the X server run binary plugins from various sources?  So we
really don't know what's going on in the process, and we should fix
this as a conservative measure (in Debian's terms, in a point release,
not through the ordinary security process).

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ