oss-sec mailing list archives
CVE request: acl 2.2.47 always follows symlinks
From: Hanno Böck <hanno () hboeck de>
Date: Wed, 23 Dec 2009 11:50:16 +0100
setfacl/getfacl (part of package acl-2.2.47) contains a bug that it ignores the --physical/-P parameter that means don't follow symlinks on -R (recursive). This can lead to security problems, e.g. if there's a cron script giving a user full rwX rights for a directory, he can put a symlink there pointing to / or /etc or whatever. Another scenario would be a backup script saving the /home acls to a file, every user can create an endless loop for that and prevent the script from completing. http://oss.sgi.com/bugzilla/show_bug.cgi?id=790 http://bugs.gentoo.org/show_bug.cgi?id=265425 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499076 Fixed in upstream source, but no new release yet. Please assign a CVE. -- Hanno Böck Blog: http://www.hboeck.de/ GPG: 3DBD3B20 Jabber/Mail: hanno () hboeck de http://schokokeks.org - professional webhosting
Attachment:
signature.asc
Description: This is a digitally signed message part.
Current thread:
- CVE request: acl 2.2.47 always follows symlinks Hanno Böck (Dec 23)
- Re: CVE request: acl 2.2.47 always follows symlinks Steven M. Christey (Dec 23)
- <Possible follow-ups>
- Re: CVE request: acl 2.2.47 always follows symlinks Brandon Philips (Dec 23)