| To: | "Frank Ch. Eigler" <fche@xxxxxxxxxx> |
|---|---|
| Subject: | Re: pmwebd security (was Re: [RFC] dynamic container switching) |
| From: | Nathan Scott <nathans@xxxxxxxxxx> |
| Date: | Sun, 8 Nov 2015 22:16:30 -0500 (EST) |
| Cc: | PCP <pcp@xxxxxxxxxxx> |
| Delivered-to: | pcp@xxxxxxxxxxx |
| In-reply-to: | <20151106202554.GE2349@xxxxxxxxxx> |
| References: | <1313883527.54143616.1444783810135.JavaMail.zimbra@xxxxxxxxxx> <20151016223319.GH27211@xxxxxxxxxx> <1384643676.62705033.1445899239483.JavaMail.zimbra@xxxxxxxxxx> <20151027155234.GB9303@xxxxxxxxxx> <1185678657.63582036.1446001295613.JavaMail.zimbra@xxxxxxxxxx> <20151031022337.GC28852@xxxxxxxxxx> <1634759327.3957536.1446687727569.JavaMail.zimbra@xxxxxxxxxx> <20151106202554.GE2349@xxxxxxxxxx> |
| Reply-to: | Nathan Scott <nathans@xxxxxxxxxx> |
| Thread-index: | +BHrLahJy5BI6zCaiUn8OMhQHg6w4Q== |
| Thread-topic: | pmwebd security (was Re: [RFC] dynamic container switching) |
----- Original Message ----- > > [...] So, to be clear, it sounds like you are confirming pmwebd has > > indeed re-opened the information exposure issue from CVE-2012-3419 > > [...] > > What? No. That CVE was about [...] This is the summary, from the CVE: "Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments". (so, esp. proc.psinfo.maps, but also all proc.* instance names - not specifically about pmcd, but its more generally about exporting that sensitive information to anyone not permitted to access it). This is the third or fourth time I've explained the above though - so don't worry about it, I'll make the needed pmwebd changes this week. > pmwebd, like pmproxy, lacks detailed outgoing ACL facilities - see Again, pmproxy does not create (automatically authenticated) unix: or local-context connections on behalf of remote clients, so it is not exposed to this problem. > > > When a 1-line bash script can DoS pmcd [...] > > > > What??? Could you please supply that script? - thanks. > [...] You've forgotten to supply the "1-line bash script" ...? thanks. -- Nathan |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [pcp] pcp updates: some build/package re-jigging and QA, Nathan Scott |
|---|---|
| Next by Date: | [pcp] libpcp: unlock context before returning (#50), Ryan Doyle |
| Previous by Thread: | Re: pmwebd security (was Re: [RFC] dynamic container switching), Frank Ch. Eigler |
| Next by Thread: | Re: pmwebd security (was Re: [RFC] dynamic container switching), Frank Ch. Eigler |
| Indexes: | [Date] [Thread] [Top] [All Lists] |