Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 6 Jun 2011 14:03:07 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: pam_ssh not dropping root gid(s)

----- Original Message -----
> Hi,
> 
> In certain configs, pam_ssh is not completely dropping its privileges to
> user. It just forgets to call setgid() and initgroups(). A fix can be
> found at [1].  Can someone assign a CVE?
> 
> thx,
> Sebastian
> 
> [1] https://bugzilla.novell.com/show_bug.cgi?id=665061
> 

Is this a security flaw? From doing a little ssh-agent research, it sounds
harmless without another flaw. I'm not terribly familiar with it though, so
I could be missing something.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.