LWN.net Logo

mom: denial of service

Package(s):mom CVE #(s):CVE-2012-4480
Created:October 18, 2012 Updated:October 24, 2012
Description:

From the Fedora advisory:

Florian Weimer of the Red Hat Product Security Team found [1] that mom created PID files in /var/run as world-writable. This could allow a malicious local attacker to edit the PID file and on mom shutdown or restart, to kill some other process than the mom process, that they would not normally have access to terminate.

This is fixed upstream [2].

[1] https://bugzilla.redhat.com/show_bug.cgi?id=863178

[2] http://gerrit.ovirt.org/#/c/8366/

Alerts:
Fedora FEDORA-2012-15496 2012-10-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds