Date: Fri, 25 Nov 2011 11:55:53 +0100 From: Ludwig Nussel <ludwig.nussel@...e.de> To: oss-security@...ts.openwall.com Subject: CVE Request: colord sql injections Hi, colord did not quote user supplied strings which made it prone to SQL injections: https://bugs.freedesktop.org/show_bug.cgi?id=42904 https://bugzilla.novell.com/show_bug.cgi?id=698250 When colord runs as root and local active users are allowed to create new devices (both are the defaults AFAIK) this allows not only to corrupt colord's own database but also to leverage it to modify other databases in the system (PackageKit for example also uses sqlite). PoC available on request. cu Ludwig -- (o_ Ludwig Nussel //\ V_/_ http://www.suse.de/ SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imendörffer, HRB 16746 (AG Nürnberg)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ