OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: 002 patch and priv sep

From: Theo de Raadt (deraadtcvs.openbsd.org)
Date: Thu May 04 2006 - 05:23:00 CDT


> 002 patch for 3.9 says "crash it and to execute malicious code within
> the X server."
> What side of the privilege separated X does this apply to?

If you had read the paper Loic gave at cansecwest, the real answer is
"it does not really matter". Unfortunately only about 1% of the people
who read it understood it.