All of lore.kernel.org
 help / color / mirror / Atom feed
From: Laszlo Ersek <lersek@redhat.com>
To: "Andreas Färber" <afaerber@suse.de>
Cc: Anthony Liguori <aliguori@us.ibm.com>,
	qemu-devel@nongnu.org, qemu-stable@nongnu.org
Subject: Re: [Qemu-devel] [PATCH stable-1.1] qga: set umask 0077 when daemonizing (CVE-2013-2007)
Date: Mon, 27 May 2013 02:28:47 +0200	[thread overview]
Message-ID: <51A2A8BF.9090101@redhat.com> (raw)
In-Reply-To: <51A2A68B.9090703@suse.de>

On 05/27/13 02:19, Andreas Färber wrote:
> Am 27.05.2013 02:11, schrieb Laszlo Ersek:

>> Do you plan to backport
>>
>>   8fe6bbc qga: distinguish binary modes in "guest_file_open_modes" map
>>   2b72001 qga: unlink just created guest-file if fchmod() or fdopen()
>>           fails on it
>>
>> too? These are considered polish for the CVE fix.
> 
> I did backport both to openSUSE 12.2 - they apply without conflicts. :)
> I mainly posted this one to check if there are better QERRs to use.

I think your choices were apt.

>> Also, a side-note: existing world-writable log files etc. are not
>> recreated nor have their modes changed, so maybe a release note or some
>> such would be useful for admins ("delete your previous logfile &
>> optional unix domain socket, or change their modes manually").
> 
> Feel free to add a note to the 1.5 Release Notes - it can then be copied
> to the previous releases we backport this fix to.

Do you mean in the wiki? I'll need an account first :)

Thanks,
Laszlo

  reply	other threads:[~2013-05-27  0:26 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-05-26 13:34 [Qemu-devel] [PATCH stable-1.1] qga: set umask 0077 when daemonizing (CVE-2013-2007) Andreas Färber
2013-05-27  0:11 ` Laszlo Ersek
2013-05-27  0:12   ` Laszlo Ersek
2013-05-27  0:19   ` Andreas Färber
2013-05-27  0:28     ` Laszlo Ersek [this message]
2013-05-27 18:33     ` Laszlo Ersek
2013-05-31 18:48 ` Anthony Liguori
2013-06-04 13:59   ` Andreas Färber
2013-06-04 14:23     ` Anthony Liguori
2013-06-05  8:33       ` [Qemu-devel] [Qemu-stable] " Michael Tokarev
2013-06-05 12:43         ` Anthony Liguori

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=51A2A8BF.9090101@redhat.com \
    --to=lersek@redhat.com \
    --cc=afaerber@suse.de \
    --cc=aliguori@us.ibm.com \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-stable@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.