summaryrefslogtreecommitdiff
path: root/tools
diff options
context:
space:
mode:
authorDaniel P. Berrange <berrange@redhat.com>2013-10-09 10:59:36 +0100
committerDaniel P. Berrange <berrange@redhat.com>2013-10-21 14:03:52 +0100
commit8c3586ea755c40d5e01b22cb7b5c1e668cdec994 (patch)
treebd912922b103234767e87048c69e67d1f7fbef00 /tools
parentae53e5d10e434e07079d7e3ba11ec654ba6a256e (diff)
downloadlibvirt-8c3586ea755c40d5e01b22cb7b5c1e668cdec994.tar.gz
Only allow 'stderr' log output when running setuid (CVE-2013-4400)CVE-2013-4400-1
We must not allow file/syslog/journald log outputs when running setuid since they can be abused to do bad things. In particular the 'file' output can be used to overwrite files. Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
Diffstat (limited to 'tools')
0 files changed, 0 insertions, 0 deletions