|
Message-ID: <4A1381B1.8010007@redhat.com> Date: Wed, 20 May 2009 12:06:09 +0800 From: Eugene Teo <eugene@...hat.com> To: oss-security@...ts.openwall.com CC: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE request: kernel: problem with NFS v4 client handling of MAY_EXEC in nfs_permission Eugene Teo wrote: > Frank Filz reported: the problem is that permission checking is skipped > if atomic open is possible, but when exec opens a file, it just opens it > O_READONLY which means EXEC permission will not be checked at that time. Upstream commit: 7ee2cb7f32b299c2b06a31fde155457203e4b7dd Thanks, Eugene
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.