First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 56171
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 56171 depends on: Show dependency tree
Bug 56171 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-07-05 14:02 0000
Description|
-----------+

While auditing and experimenting with VServer procfs and vproc security
we discovered a problem sharing permissions on the procfs mounted
directories:

Within any context users are still able to change permissions on /proc,
both access permission and ownership. That is just fine as many people
would like to restrict access to /proc to the root user or a group of
trusted users.

But as changes to a procfs mountpoint do not apply to the mountpoint
itself but to procfs in general, these changes affect all contexts
(VServers) and even the host system.

All tests were done against the stable branch (1.2x) but regarding to
Herbert Poetzl, the problem exists on both devel branches (1.3.x,
1.9.x), too.

Version 1.28 (stable branch) resolves this problem.

------- Comment #1 From Tim Yamin (RETIRED) 2004-07-07 11:23:24 0000 -------
I'm waiting for the upstream VServer depelopers to release a fixed version of
the 1.3 branch, I'll add it in when they do...

------- Comment #2 From Tim Yamin (RETIRED) 2004-07-09 06:15:23 0000 -------
Removed the development branch and added in 1.28; closing this bug as FIXED.
I'll address this issue in the next batch of kernel announcements...

First Last Prev Next    No search results available      Search page      Enter new bug