Gentoo Archives: gentoo-dev

From: Tavis Ormandy <taviso@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] last rites for app-antivirus/vlnx
Date: Mon, 11 Dec 2006 17:30:51
Message-Id: 20061211172601.GB16199@sdf.lonestar.org
In Reply to: [gentoo-dev] last rites for app-antivirus/vlnx by Timothy Redaelli
1 On Sat, Dec 09, 2006 at 04:01:30PM +0100, Timothy Redaelli wrote:
2 > can't fix rpath, application check its checksum
3 >
4
5 This looks like a serious security issue, attempting to scan a file
6 named `liblnxfv.so.4` in the cwd will execute arbitrary code (by
7 installing a constructor in the dso, for example).
8
9 What was the bug number, we probably need a mask glsa for this issue.
10
11 (the security rpath checks are there for a reason, please dont disable
12 them without checking eith security team!)
13
14 Thanks, Tavis.
15
16 --
17 -------------------------------------
18 taviso@××××××××××××.org | finger me for my pgp key.
19 -------------------------------------------------------

Replies

Subject Author
Re: [gentoo-dev] last rites for app-antivirus/vlnx Tavis Ormandy <taviso@g.o>