BugTraq
Re: Buffer overflow prevention Aug 18 2003 10:16PM
Theo de Raadt (deraadt cvs openbsd org) (3 replies)
Re: Buffer overflow prevention Aug 19 2003 08:12PM
Mark Tinberg (mtinberg securepipe com)
Re: Buffer overflow prevention Aug 19 2003 06:38AM
Crispin Cowan (crispin immunix com) (2 replies)
Re: Buffer overflow prevention Aug 19 2003 07:12PM
Mariusz Woloszyn (emsi ipartners pl)
Re: Buffer overflow prevention Aug 19 2003 04:17PM
Anil Madhavapeddy (anil recoil org)
Re: Buffer overflow prevention Aug 19 2003 01:55AM
Glynn Clements (glynn clements virgin net)

Theo de Raadt wrote:

> One of these days someone is going to use the magic of a system call
> interposition mechanism such systrace; and for their application
> accidentally create an operating system behaviour that is un-POSIX,
> and some application is going to misbehave as a result of that change
> and inadvertantly this will result in the CREATION of a hole.

For a concrete example regarding POSIX 1e capabilities (which
are essentially a "system call interposition mechanism"):

http://ciac.llnl.gov/ciac/bulletins/k-064.shtml

Summary: If a root process doesn't have CAP_SETUID, attempts to give
up root privilege fail, resulting in the process continuing to run as
root.

--
Glynn Clements <glynn.clements (at) virgin (dot) net [email concealed]>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus