MOAB advisories

Alexander Leidinger Alexander at Leidinger.net
Sun Jan 14 16:43:20 UTC 2007


Quoting Bill Moran <wmoran at collaborativefusion.com> (Sun, 14 Jan 2007 11:06:36 -0500):

> Alexander Leidinger <Alexander at Leidinger.net> wrote:
> >
> > Quoting Bill Moran <wmoran at collaborativefusion.com> (Sun, 14 Jan 2007 10:15:15 -0500):
> > 
> > > "Kobajashi Zaghi" <kobajashi at gmail.com> wrote:
> > > > 
> > > > I would like to know, that these following "vulnerabilities" does
> > > > affect FreeBSD's reliability? If the answer is "yes", what version of
> > > > FreeBSD affected, when will be fixed, etc.
> > > > 
> > > > http://projects.info-pull.com/moab/MOAB-12-01-2007.html
> > > > http://projects.info-pull.com/moab/MOAB-10-01-2007.html
> > > 
> > > These folks are establishing themselves as careless, alarmist, and
> > > uneducated when it comes to kernel bugs.
> > > 
> > > In FreeBSD, the above mentioned flaws can, indeed, cause a kernel panic.
> > > However, this is intended behaviour when a corrupt filesystem is
> > > encountered.  It protects the system from serious damage that could
> > > result from trying to work with the corrupt filesystem.
> > > 
> > > The difference, that the info-pull folks seem to be too stupid to
> > > understand, is that FreeBSD does not allow mounting of filesystems
> > > by anyone other than root.
> > 
> > Except root did set the sysctl to allow this, or started a HAL daemon
> > which mounts stuff for the desktop user, or uses amd to mount stuff.
> 
> All decisions made by root.

Yes. I just wanted to point out that it only is a non-issue when root
didn't made specific configuration operations. Those configs are ok, as
long as you know about the consequences. We do not have warnings about
this in all places where we should have them.

Bye,
Alexander.

-- 
Ohh, my son doesn't stand a chance!  The whole world has gone gay!

		-- Homer Simpson
		   Homer's Phobia
http://www.Leidinger.net  Alexander @ Leidinger.net: PGP ID = B0063FE7
http://www.FreeBSD.org     netchild @ FreeBSD.org  : PGP ID = 72077137


More information about the freebsd-security mailing list