Community Packages

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#18797 - [webfs] supplementary group list is not reset with -u option.

Attached to Project: Community Packages
Opened by Matthew (piezoelectric) - Tuesday, 23 March 2010, 01:25 GMT
Last edited by Andrea Scarpino (BaSh) - Tuesday, 23 March 2010, 08:24 GMT
Task Type Bug Report
Category Upstream Bugs
Status Closed
Assigned To No-one
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

I'll start by saying I have not been able to contact Gerd Knorr - the supposed upstream developer.

When run as root, webfsd has a -u option, which allows the program to be run as a different user. However, the supplementary groups of the original process are not reset. This means that I can run:

sudo webfsd {opts} -u nobody {opts}

and the process will maintain all of the supplementary groups of root. This is bad.


(PS - There are a couple of other issues with webfs and its handling of supplementary groups and the setuid bit. I'd like to patch everything, but as I said, upstream is not responsive.)
This task depends upon

Closed by  Andrea Scarpino (BaSh)
Tuesday, 23 March 2010, 08:24 GMT
Reason for closing:  Duplicate
Additional comments about closing:   FS#18746 

Loading...