CVE-2016-2856

CVE-2016-2856

pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie lacks a namespace check associated with file-descriptor passing, which allows local users to capture keystrokes and spoof data, and possibly gain privileges, via pts read and write operations, related to debian/sysdeps/linux.mk. NOTE: this is not considered a vulnerability in the upstream GNU C Library because the upstream documentation has a clear security recommendation against the –enable-pt_chown option.

Source: CVE-2016-2856

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다