oss-sec mailing list archives

Re: kexec-tools: Multiple security flaws by management of kdump core files and ramdisk images


From: Huzaifa Sidhpurwala <huzaifas () redhat com>
Date: Fri, 07 Oct 2011 14:59:31 +0530

On 10/05/2011 10:09 PM, akuster wrote:
What version does this affect ?

My mail should have been more verbose earlier. sorry for that!

The flaw exists in the set of shell scripts, shipped with Red Hat Enterprise Linux and Fedora kexec-tools packages.

(kdump.init and mkdumprd, more specifically)

I am not sure what other distros. ship these scripts.



--
Huzaifa Sidhpurwala / Red Hat Security Response Team


Current thread: