[pulseaudio-discuss] My computer thinks I'm schizophrenic, is PA for me?
lennart at poettering.net
Fri May 7 17:07:09 PDT 2010
On Mon, 19.04.10 19:23, Jan Braun (janbraun at gmx.de) wrote:
1;2400;0c> Lennart Poettering schrob:
> > > ...and you're explicitly disallowing cross-user shm transfer. :(
> > > I guess I'll have to figure out the security implications of messing
> > > with that.
> > Well, the story goes like this: we need to make sure that a user A
> > cannot trigger a SIGBUS in processes by user B simply by ftruncating an
> > shm region A controls and B maps and accesses. Since handling SIGBUS
> > from a library context is ugly to impossible we hence generally don't
> > allow shm data transfer between users.
> Thanks for the explanation. But this is only a DoS, isn't it?
Yes, it is 'just' a DoS vulnerability.
Lennart Poettering Red Hat, Inc.
lennart [at] poettering [dot] net
http://0pointer.net/lennart/ GnuPG 0x1A015CC4
More information about the pulseaudio-discuss