Summary: | net-dialup/ppp - pppd permissions | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Konrad Karczewski <konrad.karczewski> |
Component: | New packages | Assignee: | Gentoo Dialup Developers <net-dialup> |
Status: | RESOLVED INVALID | ||
Severity: | normal | ||
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Konrad Karczewski
2006-08-05 17:12:27 UTC
pppd is used also for PPPoE, PPPoA and PPTP connections, not just for dial-up. These permissions have been used by all distros since the beggining of time (pppd security track record is fairly clean). *** Bug 143011 has been marked as a duplicate of this bug. *** Well the security track is fairly clean but not entirely spotless. As to the permissions: on Debian they're 4754 and ownership 'root:dip', and in RH 755 - there's no suid. I don't want to say it's an extremely serious vulnerability but the proposed solution in not very complicated as well. Maybe the hardened team should be involved in this discussion? |