LWN.net Logo

abrt: unnecessary setuid

Package(s):abrt CVE #(s):
Created:July 8, 2010 Updated:July 14, 2010
Description:

From the MeeGo advisory:

The file /usr/libexec/abrt-hook-python is setuid as the abrt user. As there is no explicit reason to be setuid as the abrt user, this violates best known practices for security; specifically by not using the principles of least privilege and unintentionally expanding the attackable surface area of MeeGo.

Alerts:
MeeGo MeeGo-SA-10:03 2010-07-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds