Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 26 Mar 2014 08:56:51 +0100
From: Florian Weimer <fweimer@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: KAuth security issues

On 03/26/2014 08:10 AM, Sebastian Krahmer wrote:
> I love to talk to myself, in particular via mailing lists.
> This issue seems to be addressed meanwhile via
>
> https://git.reviewboard.kde.org/r/117056/
>
> by fixing the underlying polkit qt binding.

Is the proposed change really correct?  It uses getuid() as the subject, 
which looks wrong if you want to use this wrapper to check the 
capabilities of a D-Bus peer.

-- 
Florian Weimer / Red Hat Product Security Team

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ