Gentoo Archives: gentoo-user

From: Steen Eugen Poulsen <sep@×××××××××.net>
To: gentoo-user@l.g.o
Subject: [gentoo-user] checkrestart security fix
Date: Sat, 01 Sep 2007 21:43:46
Message-Id: 46D9DA53.6040706@lix-world.net
1 Thomas de Grenier de Latour found a codeing mistake in checkrestart,
2 that allowed a shell user to trick checkrestart into running code.
3
4 This bug exist in debian-goodies at least as far back as 0.23 and I
5 inherited it into my modified version of checkrestart that I announced here.
6
7 I've implemented Thomas'es fix in my version.
8
9 http://www.arcdraco.net/~dragon/checkrestart
10
11
12 I had hoped my code would be merged into debian-goodies by now, but
13 since that doesn't seem to be happening, everyone interested in news
14 about the tool, can use this RSS to keep up to date:
15 http://www.arcdraco.net/crss/node/2

Attachments

File name MIME type
smime.p7s application/x-pkcs7-signature