Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 8 Jan 2013 21:01:19 -0700
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Sebastian Krahmer <krahmer@...e.de>
Subject: Re: CVE Request: cronie fd leak

* [2013-01-08 13:56:40 +0100] Sebastian Krahmer wrote:

>"Hello Kurt, Steve, vendors,"
>
>cronie leaks read-only fd's, please check here:
>
>https://bugzilla.novell.com/show_bug.cgi?id=786096
>
>can someone assign a CVE?

Sebastian, do you have a specific command that you're using?  I'm trying
to reproduce this in Fedora and RHEL using lvdisplay (maybe a bad
choice?) and also using "lvm vgck -v vg_thor && lvm pvs" in
/etc/crontab.

The output is mailed to me fine with no warnings?  Can you share what
command was being used to reproduce this?  It's possible that something
you added (or we added) makes this a non-issue on other platforms.

Has upstream been informed of this yet?

-- 
Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.