Re: [security] Race condition in udev

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, 2009-08-25 at 18:27 +0200, Florian Zumbiehl wrote:

> see, that's why I am trying to consult with you before trying to
> "muck around with this kind of code". However, you may have noticed
> that this message of yours was rather much void of any information
> that could help me in doing so. Also, you are welcome to fix the
> bug I was reporting using your understanding of the code, so I
> don't have to "muck around with this kind of code" - I really am
> not all that keen on doing so.
> 
But you haven't reported a bug.

You say that setting the mode of a device node before setting the
ownership is a security issue, *but* you have not demonstrated how this
might be exploited.

Since device nodes are created with root ownership, setting the mode
before the ownership is *not a concern* because it can only have less
access than afterwards.

Scott
-- 
Scott James Remnant
scott@xxxxxxxxxxxxx

Attachment: signature.asc
Description: This is a digitally signed message part


[Index of Archives]     [Linux Kernel]     [Linux DVB]     [Asterisk Internet PBX]     [DCCP]     [Netdev]     [X.org]     [Util Linux NG]     [Fedora Women]     [ALSA Devel]     [Linux USB]

  Powered by Linux