oss-sec mailing list archives

Re: radvd 1.8.2 released with security fixes


From: Solar Designer <solar () openwall com>
Date: Thu, 13 Oct 2011 22:51:22 +0400

On Thu, Oct 13, 2011 at 12:42:42PM +0530, Huzaifa Sidhpurwala wrote:
So from what i can see, the maximum harm which would occur if 
privsep_init() fails, is that radvd would effectively run in 
--singleprocess mode

I am an outside observer here (I haven't reviewed the code myself), but
doesn't the above amount to admin-configured privilege separation not
actually being enabled?  If so, this sounds like a security issue to me.

Alexander


Current thread: