Gentoo Archives: gentoo-dev

From: Tavis Ormandy <taviso@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] last rites for app-antivirus/vlnx
Date: Thu, 14 Dec 2006 12:09:31
Message-Id: 20061214120641.GA5273@sdf.lonestar.org
In Reply to: Re: [gentoo-dev] last rites for app-antivirus/vlnx by Tavis Ormandy
1 On Mon, Dec 11, 2006 at 05:26:01PM +0000, Tavis Ormandy wrote:
2 > On Sat, Dec 09, 2006 at 04:01:30PM +0100, Timothy Redaelli wrote:
3 > > can't fix rpath, application check its checksum
4 > >
5 >
6 > This looks like a serious security issue, attempting to scan a file
7 > named `liblnxfv.so.4` in the cwd will execute arbitrary code (by
8 > installing a constructor in the dso, for example).
9 >
10 > What was the bug number, we probably need a mask glsa for this issue.
11 >
12 > (the security rpath checks are there for a reason, please dont disable
13 > them without checking eith security team!)
14 >
15
16 GLSA 200612-15
17
18 Thanks, Tavis.
19
20 --
21 -------------------------------------
22 taviso@××××××××××××.org | finger me for my pgp key.
23 -------------------------------------------------------