The open() system call in f8 really broken...

Steve Grubb sgrubb at redhat.com
Thu Aug 16 01:25:52 UTC 2007


On Wednesday 15 August 2007 21:19:00 Steve Dickson wrote:
> > And yes, its conceivable the stack contents could create
> > a world writable setuid file which cannot ever be the intended operation.
>
> The key word being "conceivable"... a hole that size would have been
> found a long time ago... 

This did in-fact happen in the wild and that's why its fixed this way. Its a 
serious problem and it should be treated that way.

-Steve




More information about the Fedora-maintainers mailing list