Full Disclosure mailing list archives
Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday
From: king cope <isowarez.isowarez.isowarez () googlemail com>
Date: Sun, 2 Dec 2012 21:36:04 +0100
Correct, I tell that from experience because I've seen many configurations where the least privileged user has file privs enabled. If we leave it that way the attackers will be more happy, it's not decision to patch it or not, just a hint . Regard, Kingcope 2012/12/2 Yves-Alexis Perez <corsac () debian org>:
On dim., 2012-12-02 at 21:17 +0100, king cope wrote:My opinion is that the FILE to admin privilege elevation should be patched. What is the reason to have FILE and ADMIN privileges seperated when with this exploit FILE privileges equate to ALL ADMIN privileges.Maybe because you might not want admins to have read/write access to the filesystem anyway? Regards, -- Yves-Alexis
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- MySQL (Linux) Stack based buffer overrun PoC Zeroday king cope (Dec 01)
- Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Jeffrey Walton (Dec 01)
- Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Kurt Seifried (Dec 02)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Sergei Golubchik (Dec 02)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Huzaifa Sidhpurwala (Dec 02)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Sergei Golubchik (Dec 03)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday king cope (Dec 03)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Yves-Alexis Perez (Dec 03)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday king cope (Dec 03)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday Sergei Golubchik (Dec 03)
- Re: [oss-security] Re: MySQL (Linux) Stack based buffer overrun PoC Zeroday king cope (Dec 03)