Comment 22 for bug 1729357

Revision history for this message
Aleksa Sarai (cyphar) wrote : Re: [Bug 1729357] Re: unprivileged user can drop supplementary groups

On Thu, Feb 15, 2018 at 11:30 PM, Craig Furman
<email address hidden> wrote:
> Thanks for the credit! I did highlight that the bug was in newgidmap in
> my initial report, by the way.

No problem -- you found the issue after all. Sorry for getting the timeline
wrong, did you want me to change the credits at all? It's your call.

> Aleksa, thanks for asking for a CVE? How did you go about this? This is
> new territory to me.

You just submit the online form at https://cveform.mitre.org/. You can also go
through the project if the project is registered with MITRE. (Canonical is
registered for example, but since this bug affects all distributions and not
just Ubuntu I felt it made more sense to just submit directly.)

There didn't appear to be any way for me to add you to Cc in the form (I could
only provide a single contact address), but I can forward the mails to you.

--
Aleksa Sarai (cyphar)
www.cyphar.com