Bug#513456: trickle: may load arbitrary code from the current working directory

2009-01-30 Thread Adeodato Simó
* Robert Lemmen [Thu, 29 Jan 2009 10:19:31 +]: > On Thu, Jan 29, 2009 at 09:21:27AM +0100, Adeodato Simó wrote: > > Yesterday I was looking at the code of the trickle package, to see how > > it worked. It uses the LD_PRELOAD mechanism to load a library that will > > take care that no more band

Bug#513456: trickle: may load arbitrary code from the current working directory

2009-01-29 Thread Robert Lemmen
On Thu, Jan 29, 2009 at 09:21:27AM +0100, Adeodato Simó wrote: > Yesterday I was looking at the code of the trickle package, to see how > it worked. It uses the LD_PRELOAD mechanism to load a library that will > take care that no more bandwidth than the configured limits will be used. > > This lib

Bug#513456: trickle: may load arbitrary code from the current working directory

2009-01-29 Thread Adeodato Simó
Package: trickle Version: 1.07-5 Severity: normal Tags: upstream Hello, here's a copy of a mail I recently sent to the Security Team: -8<- Yesterday I was looking at the code of the trickle package, to see how it worked. It uses the LD_PRELOAD mechanism to load a library that will take care that