Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Pedro Giffuni
On 04/26/16 16:17, Conrad Meyer wrote: On Tue, Apr 26, 2016 at 2:13 PM, Adrian Chadd wrote: You mean "hotplug mount a malicious USB disk via some installed graphical enviornment?" NOone does that... :) Sure, but there the vulnerability is (IMO) that users are allowed to arbitrarily mount s

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Oliver Pinter
On 4/26/16, Kristof Provost wrote: > >> On 26 Apr 2016, at 23:37, Shawn Webb wrote: >> >> On Tue, Apr 26, 2016 at 11:05:38PM +0200, Kristof Provost wrote: >>> On 26 Apr 2016, at 23:01, Shawn Webb wrote: On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: > Au

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Kristof Provost
> On 26 Apr 2016, at 23:37, Shawn Webb wrote: > > On Tue, Apr 26, 2016 at 11:05:38PM +0200, Kristof Provost wrote: >> >>> On 26 Apr 2016, at 23:01, Shawn Webb wrote: >>> >>> On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: Author: kp Date: Tue Apr 26 20:36:32 2016 >>

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Shawn Webb
On Tue, Apr 26, 2016 at 11:05:38PM +0200, Kristof Provost wrote: > > > On 26 Apr 2016, at 23:01, Shawn Webb wrote: > > > > On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: > >> Author: kp > >> Date: Tue Apr 26 20:36:32 2016 > >> New Revision: 298664 > >> URL: https://svnweb.freeb

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Ngie Cooper
On Tue, Apr 26, 2016 at 2:26 PM, Shawn Webb wrote: > On Tue, Apr 26, 2016 at 11:22:32PM +0200, Kristof Provost wrote: >> >> > On 26 Apr 2016, at 23:18, Shawn Webb wrote: >> > Was secteam@ even involved, then? Seems like a user-facing kernel buffer >> > overflow ought to have involved secteam@. >>

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Shawn Webb
On Tue, Apr 26, 2016 at 11:22:32PM +0200, Kristof Provost wrote: > > > On 26 Apr 2016, at 23:18, Shawn Webb wrote: > > Was secteam@ even involved, then? Seems like a user-facing kernel buffer > > overflow ought to have involved secteam@. > > > No, it wasn???t. This bug had been open for quite a

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Kristof Provost
> On 26 Apr 2016, at 23:18, Shawn Webb wrote: > Was secteam@ even involved, then? Seems like a user-facing kernel buffer > overflow ought to have involved secteam@. > No, it wasn’t. This bug had been open for quite a while, and I just happend to see the report and look at it. > Also, the diffe

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Shawn Webb
On Tue, Apr 26, 2016 at 11:05:38PM +0200, Kristof Provost wrote: > > > On 26 Apr 2016, at 23:01, Shawn Webb wrote: > > > > On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: > >> Author: kp > >> Date: Tue Apr 26 20:36:32 2016 > >> New Revision: 298664 > >> URL: https://svnweb.freeb

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Conrad Meyer
On Tue, Apr 26, 2016 at 2:13 PM, Adrian Chadd wrote: > You mean "hotplug mount a malicious USB disk via some installed > graphical enviornment?" > > NOone does that... :) Sure, but there the vulnerability is (IMO) that users are allowed to arbitrarily mount stuff. That's a huge attack surface an

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Adrian Chadd
You mean "hotplug mount a malicious USB disk via some installed graphical enviornment?" NOone does that... :) -a ___ svn-src-head@freebsd.org mailing list https://lists.freebsd.org/mailman/listinfo/svn-src-head To unsubscribe, send any mail to "svn-src

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Conrad Meyer
On Tue, Apr 26, 2016 at 2:01 PM, Shawn Webb wrote: > On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: >> Author: kp >> Date: Tue Apr 26 20:36:32 2016 >> New Revision: 298664 >> URL: https://svnweb.freebsd.org/changeset/base/298664 >> >> Log: >> msdosfs: Prevent buffer overflow wh

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Kristof Provost
> On 26 Apr 2016, at 23:01, Shawn Webb wrote: > > On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: >> Author: kp >> Date: Tue Apr 26 20:36:32 2016 >> New Revision: 298664 >> URL: https://svnweb.freebsd.org/changeset/base/298664 >> >> Log: >> msdosfs: Prevent buffer overflow whe

Re: svn commit: r298664 - head/sys/fs/msdosfs

2016-04-26 Thread Shawn Webb
On Tue, Apr 26, 2016 at 08:36:32PM +, Kristof Provost wrote: > Author: kp > Date: Tue Apr 26 20:36:32 2016 > New Revision: 298664 > URL: https://svnweb.freebsd.org/changeset/base/298664 > > Log: > msdosfs: Prevent buffer overflow when expanding win95 names > > In win2unixfn() we expand