[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Tue, 13 Oct 2009 08:38:40 +0200
From: Thomas Biege <thomas@...e.de>
To: OSS-Security Mailinglist <oss-security@...ts.openwall.com>
Subject: CVE request: local root via setuid VBoxNetAdpCtl
Hello,
this one needs two CVE-IDs:
- shell meta char injection in popen()
- possible buffer overflow in strncpy()
http://sunsolve.sun.com/search/document.do?assetkey=1-66-268188-1
--
Bye,
Thomas
--
Thomas Biege <thomas@...e.de>, SUSE LINUX, Security Support & Auditing
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)
--
Wer aufhoert besser werden zu wollen, hoert auf gut zu sein.
-- Marie von Ebner-Eschenbach
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ