1
0
mirror of https://sourceware.org/git/glibc.git synced 2025-09-02 16:01:20 +03:00
Files
glibc/sysdeps/unix/sysv/linux
Carlos O'Donell e4608715e6 CVE-2013-2207, BZ #15755: Disable pt_chown.
The helper binary pt_chown tricked into granting access to another
user's pseudo-terminal.

Pre-conditions for the attack:

 * Attacker with local user account
 * Kernel with FUSE support
 * "user_allow_other" in /etc/fuse.conf
 * Victim with allocated slave in /dev/pts

Using the setuid installed pt_chown and a weak check on whether a file
descriptor is a tty, an attacker could fake a pty check using FUSE and
trick pt_chown to grant ownership of a pty descriptor that the current
user does not own.  It cannot access /dev/pts/ptmx however.

In most modern distributions pt_chown is not needed because devpts
is enabled by default. The fix for this CVE is to disable building
and using pt_chown by default. We still provide a configure option
to enable hte use of pt_chown but distributions do so at their own
risk.
2013-07-21 15:39:55 -04:00
..
2013-06-05 20:44:03 +00:00
2013-07-04 09:49:14 +02:00
2013-07-04 09:49:14 +02:00
2013-06-05 20:44:03 +00:00
2013-07-04 09:49:14 +02:00
2013-07-04 09:49:14 +02:00
2013-05-06 17:11:12 -07:00
2013-06-05 20:44:03 +00:00
2012-10-09 15:41:30 -07:00
2013-02-07 14:44:18 -08:00
2013-02-08 01:12:11 +00:00
2013-02-08 20:06:30 +00:00
2013-03-06 16:35:19 +01:00
2013-03-06 16:35:19 +01:00
2013-06-06 20:36:07 +02:00
2013-02-08 01:12:11 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 20:06:30 +00:00
2012-10-04 16:31:43 -07:00
2013-03-14 08:18:48 +05:30
2013-02-08 01:12:11 +00:00
2013-02-08 20:06:30 +00:00
2013-02-08 01:12:11 +00:00