1 |
On Mon, Dec 11, 2006 at 05:26:01PM +0000, Tavis Ormandy wrote: |
2 |
> On Sat, Dec 09, 2006 at 04:01:30PM +0100, Timothy Redaelli wrote: |
3 |
> > can't fix rpath, application check its checksum |
4 |
> > |
5 |
> |
6 |
> This looks like a serious security issue, attempting to scan a file |
7 |
> named `liblnxfv.so.4` in the cwd will execute arbitrary code (by |
8 |
> installing a constructor in the dso, for example). |
9 |
> |
10 |
> What was the bug number, we probably need a mask glsa for this issue. |
11 |
> |
12 |
> (the security rpath checks are there for a reason, please dont disable |
13 |
> them without checking eith security team!) |
14 |
> |
15 |
|
16 |
GLSA 200612-15 |
17 |
|
18 |
Thanks, Tavis. |
19 |
|
20 |
-- |
21 |
------------------------------------- |
22 |
taviso@××××××××××××.org | finger me for my pgp key. |
23 |
------------------------------------------------------- |