oss-sec mailing list archives

Re: ncurses fixes upstream


From: Tavis Ormandy <taviso () gmail com>
Date: Fri, 14 Apr 2023 19:35:07 -0000 (UTC)

On 2023-04-13, Mark Esler wrote:
When you publish the CVE json5, you can references the patch URL and 
relevant bug discussions to help downstream. Including the CVE number in 
the patch commit is also quite helpful.

Thank you!

We've reached out to Arch, RedHat, Canonical and other popular distros independently.

I'm curious what the attack is! ISTR that terminfo definitions can
contain shell commands by design and so are generally considered
trusted.

I remember using this trick in an exploit once :)

$ printf "exploit, iprog=/usr/bin/id,\n" | tic -
$ TERM=exploit reset
uid=1000(taviso) gid=1000(taviso)

Tavis.

-- 
 _o)            $ lynx lock.cmpxchg8b.com
 /\\  _o)  _o)  $ finger taviso () sdf org
_\_V _( ) _( )  @taviso


Current thread: