oss-sec mailing list archives

Re: /bin/su (was: CVE request -- coreutils -- tty hijacking possible in "su" via TIOCSTI ioctl)


From: Nicolas François <nicolas.francois () centraliens net>
Date: Thu, 16 Jun 2011 00:08:14 +0200

Hello,

On Wed, Jun 15, 2011 at 12:50:47PM +0200, Ondrej Vasik wrote:

For me, having it in coreutils, shadow-utils, SimplePAMApps and possibly
- in util-linux - could only cause a lot of confusion. Some
consolidation might be better.

On one hand I agree, on the other hand I remember hard time getting rid of
Debian specific patches for su.
The behavior of -c changed and since dependencies to this tool are not
traced, there were no other ways than grep'ing the whole distro for those
two letters 'su' to prepare the transition.

One first step could be to compare their features and behaviors


PS: regarding the original issue, was the CVE requested? I would need the
    number for documentation purpose.

Best Regards,
-- 
Nekral


Current thread: