search for: 195908fe

Displaying 2 results from an estimated 2 matches for "195908fe".

2017 Feb 15
0
Serious attack vector on pkcheck ignored by Red Hat
...be fixed. It is just NOT a major security issue. -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 198 bytes Desc: OpenPGP digital signature URL: <http://lists.centos.org/pipermail/centos/attachments/20170215/195908fe/attachment-0001.sig>
2017 Feb 15
2
Serious attack vector on pkcheck ignored by Red Hat
Hello Warren, On Thu, 2017-02-09 at 15:27 -0700, Warren Young wrote: > So you?ve now sprayed the heap on this system, but you can?t upload > anything else to it because noexec, so?now what? What has our > nefarious attacker gained? So the heap is set with data provided by the (local) attacker who could initialize it to his liking using either of the two memory leaks in the options