LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-24-2017, 05:34 PM   #46
suicidaleggroll
LQ Guru
 
Registered: Nov 2010
Location: Colorado
Distribution: OpenSUSE, CentOS
Posts: 5,573

Rep: Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142

Quote:
Originally Posted by crazypenguin View Post
In order to exploit that, the user needs access to the machine (can't be exploited through the network without logging in) AND it was already patched a year ago.
 
Old 01-24-2017, 05:46 PM   #47
crazypenguin
Member
 
Registered: Jun 2002
Location: Idaho
Distribution: Linux Mint, Manjaro, FreeBSD, Android
Posts: 99

Rep: Reputation: 11
Quote:
Originally Posted by suicidaleggroll View Post
In order to exploit that, the user needs access to the machine (can't be exploited through the network without logging in) AND it was already patched a year ago.
Patched? Nope not the most recent problem.

From here.
Quote:
Bug 1020601 - (CVE-2016-10156) VUL-0: CVE-2016-10156: systemd: world writable suid files local root vulnerability

Reported: 2017-01-18 10:45 UTC by Sebastian Krahmer
But thanks for helping validate my point of how systemd has been an on going security risk.
 
Old 01-24-2017, 05:50 PM   #48
suicidaleggroll
LQ Guru
 
Registered: Nov 2010
Location: Colorado
Distribution: OpenSUSE, CentOS
Posts: 5,573

Rep: Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142
Quote:
Originally Posted by crazypenguin View Post
Patched? Nope not the most recent problem.
Yes, it's the same problem as before, and was patched a year ago.

Quote:
The issue was first introduced in the systemd source code in November 2015 and was patched two months later, in January 2016, affecting only systemd v228, and receiving a fix with the release of v229.
Quote:
The systemd project is currently at version 232. As we know Linux users and hardware vendors, it's quite possible that there are quite a few machines left around running v288.
(presumably that's a typo, it should be v228)

And from the bug report:
Quote:
A flaw in systemd v228 in /src/basic/fs-util.c ...
Quote:
Sebastian Krahmer 2017-01-18 10:50:15 UTC
Apparently upstream failed to analyze the impact of this bug and so
it was silently fixed.
Quote:
The problem seems to be in v228 only.
The issue seems to be that the impact of the bug was underestimated, so while it was fixed, it was done so silently and wasn't flagged as a major security fix, so some distro maintainers ignored it.

Last edited by suicidaleggroll; 01-24-2017 at 06:01 PM.
 
1 members found this post helpful.
Old 01-24-2017, 07:39 PM   #49
crazypenguin
Member
 
Registered: Jun 2002
Location: Idaho
Distribution: Linux Mint, Manjaro, FreeBSD, Android
Posts: 99

Rep: Reputation: 11
Quote:
Originally Posted by suicidaleggroll View Post
The issue seems to be that the impact of the bug was underestimated, so while it was fixed, it was done so silently and wasn't flagged as a major security fix, so some distro maintainers ignored it.
In any event only now they are cleaning up the problem that I pointed out in my post about "Linux Systemd Flaw Gives Attackers Root Access"
 
Old 01-24-2017, 08:23 PM   #50
crazypenguin
Member
 
Registered: Jun 2002
Location: Idaho
Distribution: Linux Mint, Manjaro, FreeBSD, Android
Posts: 99

Rep: Reputation: 11
Quote:
Originally Posted by MadeInGermany View Post
systemd is an all-in-one solution that breaks Unix principle, i.e. it increases risks in terms of likeliness and severity.
I am awaiting the first "systemd shock"s already in 2017.
I share your same thoughts on systemd. ReaperX7, another LQ forum member, phrased it in this fashion.

From here:
Quote:
Originally Posted by ReaperX7 View Post
Systemd is far from completed featurewise... when completed it's entire ultimate long-term goal is to completely eliminate the need for the current GNU operating system, shell interfaces, compilers, libraries, and other kernel handling toolkits. Basically put... Linux OS (or systemd-OS if you want to be technical).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't access full journalctl from script via systemd service even though user is in systemd-journal group iwtbf Linux - Newbie 0 02-19-2016 02:44 PM
How could the cancellation of systemd-shim will affect Slackware? ReaperX7 Slackware 20 10-14-2014 08:17 PM
Limit user via SSH (AllowedUser) but how NOT to affect vsftpd? Swakoo Linux - Security 13 06-25-2007 09:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 07:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration