Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <617692586.14212107.1358958356677.JavaMail.root@redhat.com>
Date: Wed, 23 Jan 2013 11:25:56 -0500 (EST)
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Willy Tarreau <w@....eu>, Michael Scherer <misc@...b.org>,
        Steve Grubb <sgrubb@...hat.com>,
        "Steven M. Christey" <coley@...us.mitre.org>
Subject: [Security hardening] [Notification] haproxy (previously) failed to
 drop supplementary groups after setuid / setgid calls properly

Hello vendors,

  just FYI notification that haproxy upstream has recently corrected [2]
improper dropping of supplementary groups [1] after setuid / setgid
calls.

We have further investigated this issue and have reasons to believe that 
by itself this is NOT a security issue (another flaw would need to be
found in haproxy this to be actually possible to use for something interesting).

For now we are considering this fix to be a preventive measure / security
hardening (but took the time to notify you explicitly about this as you might
still want to backport it into affected versions).

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

P.S.: [1] https://bugzilla.redhat.com/show_bug.cgi?id=894626
      [2] http://git.1wt.eu/web?p=haproxy.git;a=commitdiff;h=ab012dd3

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.