|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: local root on linux 2.2.15
From: Philip Guenther (guenther
GAC.EDU)Date: Thu Jun 08 2000 - 15:18:58 CDT
- Next message: portal: "Re: Yet another heap overflow in wu-ftpd and so on..."
- Previous message: Fabian Kroenner: "Re: Password Generation during RH Linux 6.x Installation"
- In reply to: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Next in thread: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Next in thread: Rogier Wolff: "Re: local root on linux 2.2.15"
- Reply: Philip Guenther: "Re: local root on linux 2.2.15"
- Reply: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Wojciech Purczynski <wp
ELZABSOFT.PL> writes:
>Procmail seems to be affected by this hole if used as local-mailer for
>sendmail. If CAP_SETUID bit is cleared procmail doesn't drop privileges
>and may execute luser's program that mail is forwarded to in
>~user/.procmailrc with root privileges.
Question: given this bug, is it now the community expectation that every
program that setuids from 0 to non-zero should check for the presence of
this kernel bug?
The sendmail people have enhance sendmail in just such a fashion and
I'm wondering whether I, as current maintainer of procmail, should do
so to procmail. Are we going to see new versions of perl, screen,
xterm, nxterm, and rxvt (all of which are setuid root on the Linux
system in front of me) that contain code to detect this? I suspect so,
and I'll add the requisite code to procmail for the next version.
When is a kernel bug so egregious that application writers don't need to
work around it?
Philip Guenther
- Next message: portal: "Re: Yet another heap overflow in wu-ftpd and so on..."
- Previous message: Fabian Kroenner: "Re: Password Generation during RH Linux 6.x Installation"
- In reply to: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Next in thread: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Next in thread: Rogier Wolff: "Re: local root on linux 2.2.15"
- Reply: Philip Guenther: "Re: local root on linux 2.2.15"
- Reply: Wojciech Purczynski: "Re: local root on linux 2.2.15"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]