[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 03 May 2011 15:06:05 +0530
From: Huzaifa Sidhpurwala <huzaifas@...hat.com>
To: oss-security@...ts.openwall.com
CC: William Cohen <wcohen@...hat.com>, Jan Lieskovsky <jlieskov@...hat.com>,
"Steven M. Christey" <coley@...us.mitre.org>,
Stephane Chauveau <stephane.chauveau@...s-entreprise.com>,
Maynard Johnson <maynardj@...ibm.com>,
Robert Richter <robert.richter@....com>
Subject: Re: Re: CVE Request -- oprofile -- Local privilege
escalation via crafted opcontrol event parameter when authorized by sudo
Hi William,
On 05/01/2011 07:30 AM, William Cohen wrote:
>
> I don't know if this is the best way to fix this issue, but attached is a patch that filters out all but alpha numeric characters and '_'. Feedback on the patch would be appreciated.
>
It appears from the debian bug, that there may be others way to exploit
this issue as well. hence i think we need a revised patch?
--
Huzaifa Sidhpurwala / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ