Gentoo Archives: gentoo-security

From: Samuel Damashek <samuel.damashek@×××××.com>
To: gentoo-security@l.g.o
Subject: [gentoo-security] glksa-check Proof of Concept
Date: Sat, 18 Jan 2014 04:26:11
Message-Id: 52DA0237.6060304@gmail.com
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 At the request of creffett, I created a Proof of Concept for
5 glksa-check, which allows for glksa XML files to define Kernel
6 security vulnerabilities. Please realize that this is a Proof of
7 Concept, and that the interface is not the most user-friendly. The
8 code can definitely be improved as well. To test the program, untar
9 the files and copy the glksa dir to /usr/portage/metadata/. At the
10 moment, the script requires you to have /proc/config.gz enabled in
11 your kernel to read your running config options.
12
13 I have two XML files currently defined (still using the glsa.dtd
14 schema); one that is an actual vulnerability and one that is simply a
15 control that triggers on X86. To test the program, run it with the -l
16 option.
17
18 You can download the files at http://sdamashek.me/files/glksa.tar.gz
19 (not sure if the mailing lists let you attach tarballs). There is
20 definitely a lot to be improved about the application; this is just an
21 idea for how to handle notifying users about Kernel vulnerabilities
22 that affect their system. They would be released just like glsas. What
23 are the list's opinions on this?
24
25 - --
26 Samuel Damashek
27 -----BEGIN PGP SIGNATURE-----
28 Version: GnuPG v2.0.22 (GNU/Linux)
29 Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
30
31 iQEcBAEBAgAGBQJS2gI3AAoJEGw+uP08RytWFqcH/0TyfO/6CwK281F4I7xzSEmG
32 WAjbo1OybDAKmV36U3Z+3BwWOtdMLGmJ64OJ5NBvKmITXd6A5CDpB2XYafpnEWyU
33 Y/PgyUdtLD2Ir4LQeGp8d6s8rVRCr0Ewu3KwRbvRiEAvNzn8+UXyF1AnnKZ+5vxo
34 iSOonv7WJHrj0RYq3mpDJn9/OBM+ZwdN0WgpWKZxTy4gCi0lTUXx4QxCYs4ub/I1
35 6+A+KiZgIxakfjZEmUa7drRojtEY9cMKGEf7EhRDzO8DGuAMerFmGc7Hspsd8z8p
36 bD42ATg8J7M6WaCbe8Sc2YL7oIWh+X1OO6wYc0XK6/5uq/Bpi3k2LuhV0+antfQ=
37 =QgqI
38 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-security] glksa-check Proof of Concept Chris Reffett <creffett@g.o>