Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 17 Oct 2014 23:13:28 -0400 (EDT)
From: cve-assign@...re.org
To: luto@...capital.net
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE-2014-7970: Linux VFS denial of service

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> if either argument to pivot_root referred to a directory outside of
> the calling processes's chroot, then pivot_root would malfunction,
> corrupting the mount tree.

> The mitre.org description is:
[...]

We will update this based on today's disclosure of yours. The existing
text was intended to correlate with
http://www.openwall.com/lists/oss-security/2014/10/08/21 and not
necessarily specify the attack in the most general way.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJUQdoMAAoJEKllVAevmvmsjYEH/iv8nuYfAzVNLVYew3BwmzNQ
3QvS/u5U7+1hIHYBjotQ6lPOIGDu6+WgM3AYsIvvoHoC20sbkgeQfKFa1Ki8XdRg
qbTC9f4wT/1XrkrBs9N/Hj6EHJoQaqBKsA7G+EFAzkOFtRg+c3pWzW76uZzKVHhy
vIaUxL9Rof6zqORhVslK2FahfY662Sbx00K+JNRgmlnPRrJHny8zHMjnxKYkxD0l
FJUnDmm58logvlvqxs4Chx1FJJVxgCOg2TSgDMR5nd3tLp+YYmwe+BHCXHoBED51
+QVlJXHGKI5QaaNTh4nC4pJotsY7ZedLxoJlnc35oenjHw+0tXzax0Ser39iErA=
=211E
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.