Re: [Security-Discuss] msec

Michael Scherer <[email protected]> Wed, 26 Apr 2006 17:32:54 +0200
Newsgroups gmane.linux.mandrake.security.general
Organization Mandrakelinux
Message-ID <[email protected]>
Le Mercredi 26 Avril 2006 12:29, Antonio a écrit :
> Hello to all, first time writing here :).
> A couple of months ago I filed a pair of bugs related to msec to Mandriva
> bugzilla, and one of these (the major issue from my point of view) is still
> in the unconfirmed status.
> No problem here about how much time bugzilla need to take care of it, but
> since it seems strange to me I am the only one affected by this problem,
> could anyone say a word about? I'm keeping asking myself if I'm a martian
> or not :)
> The bug is # 21243

Well, first, people commented on the bug, so while no one confirmed it, i 
think this one is valid.
But the main problem is that no one have been allocated to work on msec at 
Mandriva.

As you pointed out, i think 21243 is a duplicate of the bug 19541.

And as i am gonna add on bug 19541, adding 551 instead of 550 is defeating the 
purpose of the change, as someone could simply use bruteforce attack to guess 
the content of /proc/ .
Moreever, you should then add yourself to adm group if running msec 4.

 
-- 
Michael Scherer
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________