)]}'
{
  "commit": "42eab94fff18cb1091d3501cd284d6bd6cc9c143",
  "tree": "b30e101f5503847706a7aa24455d47f5e45cf7e1",
  "parents": [
    "4656c4d61adb8dc3ee04c08f57a5cc7598814420"
  ],
  "author": {
    "name": "Vasiliy Kulikov",
    "email": "segoon@openwall.com",
    "time": "Tue Mar 15 13:35:21 2011 +0100"
  },
  "committer": {
    "name": "Patrick McHardy",
    "email": "kaber@trash.net",
    "time": "Tue Mar 15 13:35:21 2011 +0100"
  },
  "message": "netfilter: arp_tables: fix infoleak to userspace\n\nStructures ipt_replace, compat_ipt_replace, and xt_get_revision are\ncopied from userspace.  Fields of these structs that are\nzero-terminated strings are not checked.  When they are used as argument\nto a format string containing \"%s\" in request_module(), some sensitive\ninformation is leaked to userspace via argument of spawned modprobe\nprocess.\n\nThe first bug was introduced before the git epoch;  the second is\nintroduced by 6b7d31fc (v2.6.15-rc1);  the third is introduced by\n6b7d31fc (v2.6.15-rc1).  To trigger the bug one should have\nCAP_NET_ADMIN.\n\nSigned-off-by: Vasiliy Kulikov \u003csegoon@openwall.com\u003e\nSigned-off-by: Patrick McHardy \u003ckaber@trash.net\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "e95054c690c6523fbe3ebb2ddddd59f07d4e1de8",
      "old_mode": 33188,
      "old_path": "net/ipv4/netfilter/arp_tables.c",
      "new_id": "4b5d457c2d7675559cba588f605dbbff0c69b74e",
      "new_mode": 33188,
      "new_path": "net/ipv4/netfilter/arp_tables.c"
    }
  ]
}
