Re: Temporary File Creation Bug
Hubert Chan <[email protected]> Wed, 30 Mar 2005 14:30:34 -0500
| Newsgroups | gmane.linux.cluster.openmosix.mosixview |
|---|---|
| Message-ID | <84e5a6e0ca1f0e1c41b8a91e461d2fd9@evinrude> |
Cc-ing Rexotec, since they are the ones who discovered this.
Looking at the original message [1], I think this has all been fixed in
my patches [2] (20-logdirectory.diff and 50-nonodestmp.diff). At
least,
my patches:
- move the openmosixcollector files to /var/lib/openmosixcollector,
which can be made to be writable only by root
- don't use /tmp/nodes.tmp
Can someone from Rexotec confirm that this fixes the issue?
*smacking myself for not noticing earlier that this was a security
issue*
[1] http://www.securityfocus.com/archive/1/394282
[2] http://uw-dig.uwaterloo.ca/~hy3chan/patches/openmosixview/1.5/
Niels do Vos wrote:
> For the users of openMosixView:
> The vulnerability is not very severe. No need to stress,
> disable
> openMosixView or anything like that. Only local users _could_
> exploid this bug. As long as your users of the cluster behave,
> you're not in trouble.
Don't trust your local users.
--
Hubert Chan <[email protected]> - http://www.uhoreg.ca/
PGP/GnuPG key: 1024D/124B61FA
Fingerprint: 96C5 012F 5F74 A5F7 1FF7 5291 AF29 C719 124B 61FA
Key available at wwwkeys.pgp.net. Encrypted e-mail preferred.
-------------------------------------------------------
This SF.net email is sponsored by Demarc:
A global provider of Threat Management Solutions.
Download our HomeAdmin security software for free today!
http://www.demarc.com/info/Sentarus/hamr30