[krbdev.mit.edu #8717] racecondition in posix platformAccess code path

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[krbdev.mit.edu #8717] racecondition in posix platformAccess code path

Greg Hudson via RT-2
How would an attacker gain access to the path to a user's home
directory?  The path to .k5login can alternatively be configured via
[libdefaults] k5login_directory, but it seems very unlikely that an
administrator would set that path to something underneath /tmp or
similar.

Also, what would be the adverse security impact of making the .k5login
appear to exist at one moment but then be unopenable when the code
tries to open it?  It seems like that would just cause the localauth
operation to deny access.

I moderated this through because I don't think there is actually a
security issue, but please use [hidden email] to report bugs
which you believe are exploitable.
_______________________________________________
krb5-bugs mailing list
[hidden email]
https://mailman.mit.edu/mailman/listinfo/krb5-bugs