First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 122376
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 125902
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tavis Ormandy (RETIRED) <taviso@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 122376 depends on: Show dependency tree
Bug 122376 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-02-10 07:55 0000
As gentoo doesnt follow the standard of setting games to setgid a low
privileged group, any user in group games can create symlinks in
/var/games/nethack/save, allowing them to trick other users to overwriting or
creating files.

reproduce:

cd /var/games/nethack/save
ln -s /any/file/victim/owns <uid><username>.bz2

now get victim to run nethack, when they save their game target file will be
overwritten or created.

This only affects gentoo, and is not a bug in nethack.

------- Comment #1 From Chris Gianelloni (RETIRED) 2006-02-10 12:13:09 0000 -------
See, this is not *at all* what you explained to me this morning.  Had you used
*this* example, you would have convinced me that *something* needs to be done
to resolve this.  I'm still not convinced that setgid is the answer, but
something should be done. =]

------- Comment #2 From Thierry Carrez (RETIRED) 2006-02-11 14:01:26 0000 -------
Games team, please advise

------- Comment #3 From Thierry Carrez (RETIRED) 2006-02-21 09:50:17 0000 -------
Late.

------- Comment #4 From Thierry Carrez (RETIRED) 2006-03-12 03:41:49 0000 -------
Regrouping nethack / group games issues.

*** This bug has been marked as a duplicate of 125902 ***

First Last Prev Next    No search results available      Search page      Enter new bug