[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] OpenSSH Security Advisory: gcmrekey.adv



On Fri, Nov 8, 2013 at 10:56 AM, CERT OPS Marienfeldt
<cert.marienfeldt@xxxxxxxxx> wrote:
> "If exploited, this vulnerability might permit code execution
>         with the privileges of the authenticated user"
>
> might explains the absence ;-)


how many integrations and services auth without shell?  /sbin/nologin
to /sbin/privescalate ...

tough crowd.  i leave you to your preauth remote exec fantasies,

;)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/