Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 190905 - app-cdr/qpxtool: it should be possible to install it non-setuid
Summary: app-cdr/qpxtool: it should be possible to install it non-setuid
Status: RESOLVED CANTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-31 20:39 UTC by Slava Gorbunov
Modified: 2007-08-31 23:40 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Slava Gorbunov 2007-08-31 20:39:36 UTC
In qpxtool-0.6.1, several binaries (qpxtool, pxcontrol, pxfw, pioquiet) are installed setUID. I suppose that it is insecure to do this by default (because qpxtool is still in beta stage and apparently contains security-related bugs). I would suggest to install binaries setuid only if 'suid' USE-flag is set.

Reproducible: Always
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-08-31 23:40:08 UTC
Yeah, it certainly would... except that those tools won't work properly after you've done it, because these tools require low-level hardware accesss. But it will be very secure. ;)