|
|
| |
|
| |
abrt: unnecessary setuid
| Package(s): | abrt |
CVE #(s): | |
| Created: | July 8, 2010 |
Updated: | July 14, 2010 |
| Description: |
From the MeeGo advisory:
The file /usr/libexec/abrt-hook-python is setuid as the abrt user.
As there is no explicit reason to be setuid as the abrt user, this
violates best known practices for security; specifically by not using
the principles of least privilege and unintentionally expanding the
attackable surface area of MeeGo.
|
| Alerts: |
|
( Log in to post comments)
|
|
|