<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>24572</bug_id>
          
          <creation_ts>2003-07-16 00:58 0000</creation_ts>
          <short_desc>stunnel 4.02 uid/gid nobody/nogroup is insecure</short_desc>
          <delta_ts>2003-10-28 07:23:24 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Applications</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>raimund@spemaus.de</reporter>
          <assigned_to>aliz@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>raimund@spemaus.de</who>
            <bug_when>2003-07-16 00:58:20 0000</bug_when>
            <thetext>The config file stunnel.conf which is installed by default attempts to start
stunnel setuid nobody and setgid nogroup. Generally it is not advisable to run
daemons setuid nobody because if there is more than one such program, they could
ptrace or send signals to each other.

The ebuild should better create dedicated user and group &quot;stunnel&quot;.

Reproducible: Always
Steps to Reproduce:</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aliz@gentoo.org</who>
            <bug_when>2003-10-28 07:23:24 0000</bug_when>
            <thetext>Incorporated in 4.04-r2, please test.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>