Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 190905

Summary: app-cdr/qpxtool: it should be possible to install it non-setuid
Product: Gentoo Linux Reporter: Slava Gorbunov <slava>
Component: Current packagesAssignee: Gentoo Linux bug wranglers <bug-wranglers>
Status: RESOLVED CANTFIX    
Severity: normal    
Priority: High    
Version: 2006.1   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Slava Gorbunov 2007-08-31 20:39:36 UTC
In qpxtool-0.6.1, several binaries (qpxtool, pxcontrol, pxfw, pioquiet) are installed setUID. I suppose that it is insecure to do this by default (because qpxtool is still in beta stage and apparently contains security-related bugs). I would suggest to install binaries setuid only if 'suid' USE-flag is set.

Reproducible: Always
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-08-31 23:40:08 UTC
Yeah, it certainly would... except that those tools won't work properly after you've done it, because these tools require low-level hardware accesss. But it will be very secure. ;)