home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!sol.ctr.columbia.edu!ira.uka.de!math.fu-berlin.de!unidui!Germany.EU.net!mcsun!julienas!acri.acri.fr!acri!mellan
- From: mellan@syst06.acri.fr (Alain Mellan)
- Subject: gnumake SGID: potential security hole?
- Message-ID: <MELLAN.92Nov17131950@syst06.acri.fr>
- Sender: news@acri.fr
- Organization: A.C.R.I., Lyon, France
- Date: Tue, 17 Nov 1992 12:19:50 GMT
- Lines: 16
-
-
- I just discovered today that gnumake is installed with SGID bit, and
- belongs to user root, group kmem.
-
- Am I right to be suspicious ? The kmem SGID will allow gnumake to
- read into /dev/kmem the info needed for load balancing, but is that
- all?
-
-
-
- --
- Alain Mellan
- Advanced Computer Research Institute
- 1 Bvd Marius Vivier Merle voice: (+33) 72 35 84 92
- 69443 LYON CEDEX 03 - FRANCE email: amellan@acri.fr
-
-