oss-sec mailing list archives
Re: Re: MySQL - use-after-free after mysql_stmt_close()
From: Kurt H Maier <khm () sciops net>
Date: Thu, 15 Jun 2017 10:28:04 -0700
On Thu, Jun 15, 2017 at 08:21:29AM -0600, Kurt Seifried wrote:
1) Official documentation that says "do this [insecure thing]" should probably get a CVE (e.g. "turn off all the encryption to make it work more easily"). This should probably get a CVE, especially as it results in operational changes which won't get a CVE (since it's not in code that "ships", it's just on the end of whoever is using it).
I really like this idea. What would be the approach to software whose documentation starts out with "turn off selinux," out of curiosity? Obviously this lessens the security stance of the system, but presumably the system is designed to be operable without selinux. Would CVEs get assigned for all bad ideas, or just those that expose actual attack vectors?
3) Unofficial but commonly used documentation and code examples, I guess the best example here is stackoverflow and friends?
This is going to cause you to hit INT_MAX relatively quickly. khm
Current thread:
- MySQL - use-after-free after mysql_stmt_close() Pali Rohár (Jun 08)
- Re: MySQL - use-after-free after mysql_stmt_close() Pali Rohár (Jun 12)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Adam Maris (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Kurt Seifried (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Kurt H Maier (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() kseifried () redhat com (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Seth Arnold (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Adam Maris (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Feng Cao (Jun 15)
- Re: Re: MySQL - use-after-free after mysql_stmt_close() Brian May (Jun 15)
- Re: MySQL - use-after-free after mysql_stmt_close() Pali Rohár (Jun 12)