Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 11 Jun 2012 18:21:19 +0200
From: Petr Matousek <pmatouse@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE request -- libguestfs: virt-edit doesn't preserve file
 permissions

Description of the problem:
virt-edit creates a new file when it is used and thus does not
preserve file permissions, file owner and SELinux context on the
files that it was editing.

As a consequence, if certain security-sensitive files in the guest
were edited using virt-edit, they would become world-readable.

Proposed upstream patch:
https://www.redhat.com/archives/libguestfs/2012-February/msg00034.html

References:
https://www.redhat.com/archives/libguestfs/2012-February/msg00033.html
https://bugzilla.redhat.com/show_bug.cgi?id=788642

Thanks,
-- 
Petr Matousek / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.