[Bug 95] New: kapabilities caches root password - major security issue
bugzilla-daemon <[email protected]>
| Newsgroups | gmane.linux.arklinux.bugs |
|---|---|
| Message-ID | <[email protected]> |
https://bugzilla.arklinux.org/bugzilla/show_bug.cgi?id=95
Summary: kapabilities caches root password - major security issue
Product: Ark Linux
Version: 1.0 alpha6
Platform: i586 (PC, Intel)
OS/Version: All
Status: NEW
Severity: Security
Affects: Overall Usability
Component: kapabilities
AssignedTo: [email protected]
ReportedBy: [email protected]
QAContact: [email protected]
Description of Problem:
After running the "kapabilities"
Version-Release number of selected component (if applicable):
kapabilities - default version, ArkLinux 1.0 A6
su (coreutils) 4.5.3
How Reproducible:
Every time
Steps to Reproduce:
1. use kapabilities to "switch user IDs with root"
2. the root password is cached
3. this is evil, pure evil
Actual Results:
no need to type a password to do "root" things
Expected Results:
need to enter a password to access root functions
Additional Information:
This is a major security issue. If the user is not added to the "switch user
IDs with root" then they cannot even use the "su" command to gain root. If they
have this option selected, then they no longer need to enter a root password for
command line root functions.
This is a major security issue - akin to the Lindows "every user has root"
issue, and will result in ArkLinux (unfortunately) not being able to be
implemented in many businesses where security is an issue - which should be
every business network.
I recommend that this be addresses ASAP as caching the root password is evil.
Disallowing users to "su" may well be a worthwhile feature, and allowing only
certain users to be able to "su" can be quite beneficial. Cching the root
password is just not good.
I do also have an issue with the default login as "arklinux" which also has root
access, even when new users are added to the system. Default log in is also
pure evil.
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.
You are the QA contact for the bug, or are watching the QA contact.