Skip to content

Remove extra options #98

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Feb 16, 2020
Merged

Remove extra options #98

merged 1 commit into from
Feb 16, 2020

Conversation

danfruehauf
Copy link
Owner

After analyzing some privilege escalation possibilites, it was decided
it is best to remove extra options

After analyzing some privilege escalation possibilites, it was decided
it is best to remove extra options
@danfruehauf
Copy link
Owner Author

I understand some people are going to be very unhappy with it. However I hope to add -L and -R options.

See also:
https://bugzilla.redhat.com/show_bug.cgi?id=1803499

@danfruehauf
Copy link
Owner Author

@lhw This should be urgently deployed. I'll tag it as 1.2.11

@danfruehauf danfruehauf merged commit 8f5de0b into master Feb 16, 2020
@danfruehauf danfruehauf deleted the remove_extra_opts branch February 16, 2020 19:03
@carnil
Copy link

carnil commented Feb 17, 2020

@danfruehauf can you please request a CVE as needed for the privilege escalation flaw via https://cveform.mitre.org/ ?

@kobus-v-schoor
Copy link

@carnil I've requested a CVE ID and will post it here once I've heard back from them.

@carnil
Copy link

carnil commented Feb 22, 2020

@kobus-v-schoor was there any news on the CVE assignment?

@carnil
Copy link

carnil commented Feb 22, 2020

@danfruehauf https://bugzilla.redhat.com/show_bug.cgi?id=1803499 is not publicly accessible, possible to open that up? This might be blocking the CVE assignment from MITRE if they have not enough context.

@carnil
Copy link

carnil commented Feb 23, 2020

CVE-2020-9355 was assigned for this issue.

@purpleidea
Copy link

Darn. I can't -D anymore. Is there some way to add this? :(

@12345ieee
Copy link

The PR removed the extra options, but left in the README section and the image, giving the false impression this is still supported.

On the same topic, I'd really like to have -L back, would you be open to merge a very restricted input field that just allows the user to append valid -L blocks?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants