Kovid: No, you haven't.  Your code contains a race condition that allows
a bypass of the checks you've put in place.  Here's another exploit.
You can warn and ignore me all you want, it doesn't make this code any
safer.

** Attachment added: "Yet another exploit"
   
https://bugs.launchpad.net/calibre/+bug/885027/+attachment/2584435/+files/70calibrerassaultmount.sh

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/885027

Title:
  SUID Mount Helper has 5 Major Vulnerabilities

To manage notifications about this bug go to:
https://bugs.launchpad.net/calibre/+bug/885027/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to