oss-sec mailing list archives

Re: CVE request: init script x11-common creates directories in insecure manners


From: "Jason A. Donenfeld" <Jason () zx2c4 com>
Date: Thu, 1 Mar 2012 16:43:17 +0100

On Thu, Mar 1, 2012 at 13:11, vladz <vladz () devzero fr> wrote:

Yes, this is a Debian / Ubuntu specific issue.

This issue might be mitigated by kernel.yama.protected_stick_symlinks,
which is present at least on Ubuntu.

Current thread: