public inbox for glibc-bugs@sourceware.org
help / color / mirror / Atom feed
* [Bug libc/15755] New: CVE-2013-2207: pt_chown tricked into granting access to another users pseudo-terminal
@ 2013-07-19  4:20 carlos at redhat dot com
  2013-07-19  4:20 ` [Bug libc/15755] " carlos at redhat dot com
                   ` (8 more replies)
  0 siblings, 9 replies; 10+ messages in thread
From: carlos at redhat dot com @ 2013-07-19  4:20 UTC (permalink / raw)
  To: glibc-bugs

http://sourceware.org/bugzilla/show_bug.cgi?id=15755

            Bug ID: 15755
           Summary: CVE-2013-2207: pt_chown tricked into granting access
                    to another users pseudo-terminal
           Product: glibc
           Version: 2.18
            Status: NEW
          Severity: normal
          Priority: P2
         Component: libc
          Assignee: unassigned at sourceware dot org
          Reporter: carlos at redhat dot com
                CC: drepper.fsp at gmail dot com

A security flaw was found in the way pt_chown, a helper function for grantpt(3)
to change ownership and permissions of pseudoterminal, of glibc, the collection
of GNU libc libraries, performed pseudotty ownership and permission changes
when granting access to the slave pseudoterminal. A local attacker could use
this flaw to obtain unauthorized read / write access at the pseudoterminal of
their choose by using a specially-crafted (by attacker supplied) file system.

Acknowledgements:

Red Hat would like to thank Martin Carpenter of Citco for reporting this issue.

-- 
You are receiving this mail because:
You are on the CC list for the bug.


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2015-02-23 15:03 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-07-19  4:20 [Bug libc/15755] New: CVE-2013-2207: pt_chown tricked into granting access to another users pseudo-terminal carlos at redhat dot com
2013-07-19  4:20 ` [Bug libc/15755] " carlos at redhat dot com
2013-07-19  5:58 ` carlos at redhat dot com
2013-07-21 19:43 ` carlos at redhat dot com
2014-02-16 19:43 ` jackie.rosen at hushmail dot com
2014-05-28 19:44 ` schwab at sourceware dot org
2014-06-13  9:23 ` fweimer at redhat dot com
2015-01-16 16:59 ` cvs-commit at gcc dot gnu.org
2015-01-29 18:50 ` cvs-commit at gcc dot gnu.org
2015-02-23 15:03 ` cvs-commit at gcc dot gnu.org

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).