[Bug 95] New: kapabilities caches root password - major security issue

bugzilla-daemon <[email protected]>
Newsgroups gmane.linux.arklinux.bugs
Message-ID <[email protected]>
https://bugzilla.arklinux.org/bugzilla/show_bug.cgi?id=95

           Summary: kapabilities caches root password - major security issue
           Product: Ark Linux
           Version: 1.0 alpha6
          Platform: i586 (PC, Intel)
        OS/Version: All
            Status: NEW
          Severity: Security
           Affects: Overall Usability
         Component: kapabilities
        AssignedTo: [email protected]
        ReportedBy: [email protected]
         QAContact: [email protected]


Description of Problem:

After running the "kapabilities"


Version-Release number of selected component (if applicable):

kapabilities - default version, ArkLinux 1.0 A6
su (coreutils) 4.5.3


How Reproducible:

Every time


Steps to Reproduce:
1. use kapabilities to "switch user IDs with root"
2. the root password is cached
3. this is evil, pure evil


Actual Results:

no need to type a password to do "root" things


Expected Results:

need to enter a password to access root functions


Additional Information:

This is a major security issue.  If the user is not added to the "switch user
IDs with root" then they cannot even use the "su" command to gain root.  If they
have this option selected, then they no longer need to enter a root password for
command line root functions.

This is a major security issue - akin to the Lindows "every user has root"
issue, and will result in ArkLinux (unfortunately) not being able to be
implemented in many businesses where security is an issue - which should be
every business network.

I recommend that this be addresses ASAP as caching the root password is evil. 
Disallowing users to "su" may well be a worthwhile feature, and allowing only
certain users to be able to "su" can be quite beneficial.  Cching the root
password is just not good.

I do also have an issue with the default login as "arklinux" which also has root
access, even when new users are added to the system.  Default log in is also
pure evil.



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.
You are the QA contact for the bug, or are watching the QA contact.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.