User: Password:
|
|
Subscribe / Log in / New account

A privilege escalation flaw in udev

A privilege escalation flaw in udev

Posted Apr 23, 2009 17:08 UTC (Thu) by jimparis (subscriber, #38647)
In reply to: A privilege escalation flaw in udev by BenHutchings
Parent article: A privilege escalation flaw in udev

That is not true. Go look at Kay's commit. It adds the SO_PASSCRED option to the socket and adds an explicit check for (cred->uid != 0). As the LWN writeup indicated, 'either patch "alone would be sufficient" to fix the problem'. And your statement about him being quick to notify others is misleading at best. There has still not been a single posting on the udev mailing list about this problem!


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds