oss-sec mailing list archives
CVE-Request for brltty auth bypass
From: Sebastian Krahmer <krahmer () suse com>
Date: Tue, 12 Apr 2016 09:49:37 +0200
Hi
brltty is using polkit to control access to system ressources
("Write to the braille display").
It is doing so by using the PID of the process connecting
to the server socket. This is racy. The unix polkit subject
is deprecated, but if its used, the UID should be specified
as well, so it doesnt get looked up in /proc.
I already contacted upstream (Cc) but so far no response.
You can find my (untested) proposed patch at:
https://bugzilla.suse.com/show_bug.cgi?id=967436
Its probably not the worst issue, but should be fixed
nevertheless.
Sebastian
--
~ perl self.pl
~ $_='print"\$_=\47$_\47;eval"';eval
~ krahmer () suse com - SuSE Security Team
Current thread:
- CVE-Request for brltty auth bypass Sebastian Krahmer (Apr 12)
- Re: CVE-Request for brltty auth bypass Dave Mielke (Apr 12)
- Re: CVE-Request for brltty auth bypass cve-assign (Apr 13)
