|
Message-ID: <1441798244.1020639.1315588834916.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com> Date: Fri, 9 Sep 2011 13:20:34 -0400 (EDT) From: Josh Bressers <bressers@...hat.com> To: oss-security@...ts.openwall.com Cc: Sebastian Krahmer <krahmer@...e.de>, Guido Berhoerster <gber@...nsuse.org> Subject: Re: Re: lightdm issues Here you go: CVE-2011-3349 lightdm files written as root to user-controlled folders Thanks. -- JB ----- Original Message ----- > On ven., 2011-08-26 at 14:51 +1000, Robert Ancell wrote: > > Hi Sebastian, > > > > Thanks for doing this review, this issue is now being tracked in the > > LightDM issue tracker: > > https://bugs.launchpad.net/lightdm/+bug/834079 > > Could a CVE be assigned? Sebastian didn't really asked for it but as > it > can indeed be used to overwrite root-owned files (with non-controlled > content afaict) I guess it deserves ones? > > Regards, > -- > Yves-Alexis
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.