Re: [linux-cifs-client] [PATCH] Remove information leak in Linux CIFS clientg

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Steve French <smfrench@...>
Cc: Andi Kleen <andi@...>, simo <idra@...>, <linux-kernel@...>, <linux-cifs-client@...>, <samba-technical@...>
Date: Saturday, January 19, 2008 - 7:25 pm

On Sat, Jan 19, 2008 at 04:55:53PM -0600, Steve French wrote:

The problem is that the file name ends up in the log for everybody to
read even if they're totally unrelated. So if someone in a protected directory
tree where they have access to does something that is denied the
file names will still leak to everybody else to the log.

e.g. more concrete example. you do something and get that message.

Now even 'nobody" running in a chroot will know that you tried
that and that at least parts of the file name likely exist.

That is an information leak and imho a privacy problem.


Sure errors should be logged, but not with path names. 

-Andi
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] Remove information leak in Linux CIFS client, Andi Kleen, (Sat Jan 19, 12:55 am)
Re: [linux-cifs-client] [PATCH] Remove information leak in L..., Andi Kleen, (Sat Jan 19, 7:25 pm)