Home page logo

oss-sec logo oss-sec mailing list archives

CVE request: perf: may parse user-controlled config file
From: dann frazier <dannf () debian org>
Date: Sun, 7 Aug 2011 11:34:38 -0600

This was reported by Christian Ohm at:

The perf command, provided as part of the Linux kernel source, looks
for and honors configuration settings in ./config. A local user could
obtain elevated privileges by convincing a superuser to run the perf
command from a directory the user controls.

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]