Date: Wed, 17 Dec 2008 16:32:07 +0100 From: Marcus Meissner <meissner@...e.de> To: oss-security@...ts.openwall.com Cc: Eugene Teo <eugeneteo@...nel.sg>, "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: Re: CVE request: kernel: applicom: fix an unchecked user ioctl range On Tue, Dec 16, 2008 at 09:24:32PM -0500, Steven M. Christey wrote: > > On Wed, 17 Dec 2008, Eugene Teo wrote: > > > Hmm, there's a comment in the ac_ioctl() that the device for this is > > only accessible by root, so if out of range may not matter. Hmm. So, > > maybe, maybe not. > > Our current approach would be, probably not. I guess the accessibility very much depends on the /dev/ac* device permissions here. For a multiport serial card I guess root/tty only. Ciao, Marcus
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.