Re: Do people exaggerate in security advisories?

2008-01-04 Thread Valdis . Kletnieks
On Fri, 04 Jan 2008 13:21:32 +0100, Manuel Reimer said: > Is it really possible to get root privileges with this bug or are there > people who just write "may be used to escalate privileges" near any bug > which has something to do with "setuid" or "setgid"? It looks like it really *is* possibl

Re: Do people exaggerate in security advisories?

2008-01-04 Thread Manuel Reimer
Hello, Shame on me, but I didn't look carefully at the patch. The patch, of course, tries to get rid of root privileges and doesn't try to get them. As I also posted to the wrong list, by accident, lets assume this topic as closed. Yours Manuel Reimer -- To unsubscribe from this list: send

Do people exaggerate in security advisories?

2008-01-04 Thread Manuel Reimer
Hi, I found this one today: http://securitytracker.com/alerts/2007/Oct/1018782.html In the git changelog: http://git.kernel.org/?p=utils/util-linux-ng/util-linux-ng.git;a=commit;h=ebbeb2c7ac1b00b608390595783 7a271e80b187e noone leaves any word about privilege escalation. Is it really possibl