[PATCH] Harden put*ent functions against data injection [BZ #18724]
Florian Weimer
fweimer@redhat.com
Mon Jul 27 15:19:00 GMT 2015
This patch addresses a âBobby Tablesâ issue in the put*ent functions and
the getent program, similar to one of the recent libuser issues.
I believe this is just hardening because users of the put*ent functions
already have appropriate checks before they call these functions, so
this is definitely post-freeze material.
Tested on x86_64-redhat-linux-gnu. Okay to commit after master reopens?
--
Florian Weimer / Red Hat Product Security
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Harden-putpwent-putgrent-putspent-putspent-against-i.patch
Type: text/x-patch
Size: 40817 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20150727/ed9fa67e/attachment.bin>
More information about the Libc-alpha
mailing list