[VulnDiscuss] Re: Dangerous permissions in unitedlinux
Roman Drahtmueller <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hello Knud, While all of the four UnitedLinux partners Conectiva, SCO, TurboLinux and SuSE have greatly contributed to what UnitedLinux is today, SuSE has the role of the product integrator of UnitedLinux 1.0. I'm answering as head of security at SuSE. > Attached document explains all. > > Rant: People using a product called 'antigen' should be shot, stabbed, and No comment on the rant... [quotes strongly shortened] > According to the vendor "UnitedLinux addresses enterprise customers' > needs for a high quality, low cost, standards-based Linux environment > that enables the widespread adoption of Linux." > II. DESCRIPTION > The folders below /usr/src/packages/ ships with the following permissions: > drwxrwxrwt, which makes it writeable by all users. > III. ANALYSIS > This makes way for planting of rogue source, ultimately leading to a full > system compromise. > IV. DETECTION > UnitedLinux 1.0 (i586) beta3 is found to be vulnerable. Generally, it might be a bad idea to report security related problems in a beta after the product has been released. But anyway: The final UnitedLinux 1.0 products contain the same setup: All directories within /usr/src/packages are world-writeable with the t-flag set (mode 1777). The modes have been set like this intentionally to make it possible for a non-root user to (re)build packages using the command 'rpm --rebuild package.spm'. By consequence, this is a tradeoff: Either you don't provide the modes necessary for non-root package builds, or you take the risk that somebody plants an egg in those directories. > V. WORKAROUND > > Change the permissions on > /usr/src/packages/* and below to something more suitable. We have thought of an easier way than changing the modes manually: vi /etc/sysconfig/security and change PERMISSION_SECURITY from "easy local" to "secure local". Afterwards, either run SuSEconfig or 'chkstat -set /etc/permissions.secure'. > VI. VENDOR FIX > > unknown None. > IX. CREDIT > Knud Erik Højgaard/kokanin[a]dtors.net Thanks, Roman Drahtmüller, SuSE Security. - - - -- - - | Roman Drahtmüller <[email protected]> // "You don't need eyes to see, | SuSE Linux AG - Security Phone: // you need vision!" | Nürnberg, Germany +49-911-740530 // Maxi Jazz, Faithless | - - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: SuSE Security iQEVAwUBPpHcWney5gA9JdPZAQH7yQf+LEjvjEmBO8pLT3zOTSnC1GwKc5xMx8Kc MB4v6cspjvg903L+6COGGFM4fDYuXjinPfEaefjc24Pbs605Sk1l7qqHj3EmZsyk zcQNmXX+H1UE3E2+ymsYpxdTO0qiGAYRSj7ZfllnPVhW0iK0fOnkuGhRB9I7EoeU m8A+Zkibh+uf5xQdi8H1gryGO6g0ZYckTJxCcMnKu9fOyqy1XZK2eORAhNVlk3La y9BZYd2bkVu1U3T8GrtfPDDsHV7PD7A3i//EUzvy7OtfGFBL6knIsOTpKWGh14lB Rm/lU6h3hk/XALrOckfSIoZPsXXsWTvs60Sn7do+LuU3WGo7PtJjEQ== =HKqD -----END PGP SIGNATURE-----