Handle older versions of the Linux kernel in a safer way
The Linux kernel does argument splitting after parameter expansion, leading to an attacker on old kernels being able control the owner variable, leading to the creation of bogus root-owned directories. Fixes: https://bugs.debian.org/924398 Reported-by:Jakub Wilk <jwilk@jwilk.net> Reported-in: <20190312145043.jxjoj66kqssptolr@jwilk.net>
Loading
Please register or sign in to comment