MAJOR hole in 5.0

Ian Molton <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization The Dragon Roost
Message-ID <[email protected]>
Hi.

I dont want to steal anyones thunder at all by this but anyone who built
a 5.0pre1 is subject to a pretty major security hole.

the 'nobody' user in /etc/passwd is wrong. anyone building 5.0 should
check this is not screwed on their build.

it SHOULD be:

nobody:x:1000:1000:::/bin/false

and not:

nobody:x:1000:1000:nobody:/:/bin/bash

hole found by voidcore on IRC.
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.