|
Message-ID: <4BFB5899.9080205@kernel.sg> Date: Tue, 25 May 2010 12:56:57 +0800 From: Eugene Teo <eugeneteo@...nel.sg> To: oss-security@...ts.openwall.com CC: "Steven M. Christey" <coley@...us.mitre.org> Subject: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership Besides checking the write permissions, the setflags ioctl should also be checking for the ownership of the file. It's a minor issue but the behaviour is unexpected. References: https://bugzilla.redhat.com/show_bug.cgi?id=595579 http://www.linux-archive.org/cluster-development/375481-gfs2-fix-permissions-checking-setflags-ioctl.html Thanks, Eugene -- main(i) { putchar(182623909 >> (i-1) * 5&31|!!(i<7)<<6) && main(++i); }
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.