[Security-Discuss] Xine accessing /etc/passwd ????
Tuxiq <tuxiq2304-FFYn/[email protected]> Sun, 21 May 2006 09:36:05 -0400
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
OK guys this is my first post so I apologize in advance for any mistakes... I noticed my latest XINE, when started from a konsole and provided with a filename on the command line, suddenly started giving me the following message when exiting .... mkdir(/spook) failed: Permission denied where "spook" is my normal user name. So I was curious and did an STRACE of xine which revealed that something in the process was accessing the /etc/passwd file and looking up the <root> entry !!????? IS THIS NORMAL BEHAVIOUR??????? In any case I am attaching the strace output. OH and while I'm at it, while preparing the attachment I managed to delete a file belonging to root:root with only READ access writes to group members or others, and this is not the first time the system allowed me to do this. The only possible mitigating factor is that it happened in my home directory and my user has full sudo rights but I had not even invoked sudo in that session so there was no possibility of "RESIDUAL" rights from a prior invocation. ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________
xine_possible_security_risk.txt
(text/plain, 509.2 KB) - not displayed