Bug#630699: CVE-2011-1089: /etc/mtab corruption

2011-06-18 Thread Aurelien Jarno
On Thu, Jun 16, 2011 at 01:51:15PM +0200, Arne Wichmann wrote: > Package: libc6 > Version: 2.13-4 > Severity: normal > Tags: patch > > >From the security tracker: > > The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and > earlier does not report an error status for failed att

Bug#630699: CVE-2011-1089: /etc/mtab corruption

2011-06-16 Thread Arne Wichmann
Package: libc6 Version: 2.13-4 Severity: normal Tags: patch >From the security tracker: The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to tr