[CentOS] Serious attack vector on pkcheck ignored by Red Hat

John R Pierce pierce at hogranch.com
Thu Feb 2 14:40:21 UTC 2017


On 2/2/2017 6:22 AM, Leonard den Ottolander wrote:
> However, the fact that the binary in the example is setuid is orthogonal
> to the fact that heap spraying is a very serious attack vector.

without privilege escalation, what does it attack ?


-- 
john r pierce, recycling bits in santa cruz




More information about the CentOS mailing list