MAJOR hole in 5.0
Ian Molton <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | The Dragon Roost |
| Message-ID | <[email protected]> |
Hi. I dont want to steal anyones thunder at all by this but anyone who built a 5.0pre1 is subject to a pretty major security hole. the 'nobody' user in /etc/passwd is wrong. anyone building 5.0 should check this is not screwed on their build. it SHOULD be: nobody:x:1000:1000:::/bin/false and not: nobody:x:1000:1000:nobody:/:/bin/bash hole found by voidcore on IRC. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page