Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
05-03-2006, 02:29 AM
|
#1
|
Member
Registered: Dec 2003
Location: Roc City (Rochester-NY)
Distribution: Slacker 4 Life
Posts: 125
Rep:
|
X Windows Systems allows execute as root
Did anyone else see this??:
http://news.yahoo.com/s/zd/20060502/tc_zd/177195
I just stumbled upon it, I would think this would be posted just about everywhere you look (linux-wise). Am I missing something??
|
|
|
05-03-2006, 11:06 AM
|
#3
|
Member
Registered: Dec 2003
Location: Roc City (Rochester-NY)
Distribution: Slacker 4 Life
Posts: 125
Original Poster
Rep:
|
No, not the first bug, but due to the massive use of X11 on *nix machines (moreso than any other app?!) and the seriousness of the vulnerability I wasn't expecting to just happen across it while trolling the net.
|
|
|
05-03-2006, 12:54 PM
|
#4
|
Member
Registered: Feb 2005
Location: Ontario, Canada
Distribution: Gentoo, Slackware
Posts: 345
Rep:
|
Most security exploits are published to the net to inform the users.
The users can then either download a patch if available, or switch to a different version where the exploit doesn't exist, etc...
If they didn't publish the exploits then people would ignorantly continue using vulnerable software while wily crackers slip into their systems.
|
|
|
05-03-2006, 01:30 PM
|
#5
|
LQ Guru
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870
|
Quote:
Originally Posted by TomaCzar
No, not the first bug, but due to the massive use of X11 on *nix machines (moreso than any other app?!) and the seriousness of the vulnerability I wasn't expecting to just happen across it while trolling the net.
|
i actually saw the news published on tons of websites - i guess it depends on one's surfing habits... either way, it's not a highly critical issue IMHO (AFAIK to exploit it you'd have to be authorized to connect to the X server)... BTW, it should be noted that the patch fixes two separate issues: one is the parenthesis issue found by coverity (who are getting great publicity from this, BTW), and the other is a single-character typo in the same file (an ampersand instead of an asterisk)...
|
|
|
05-03-2006, 09:16 PM
|
#6
|
Member
Registered: Jun 2005
Location: Indiana, USA
Distribution: OpenBSD, Ubuntu
Posts: 892
Rep:
|
It's kinda funny to me, since X is such a large and very complex piece of software, that the only people I've heard of running privilege separation and drops on X are the OpenBSD folks. We all know they're a paranoid bunch, and the world (and my servers) are better for it. But has anybody else made the X server run as a non-privileged user?
|
|
|
All times are GMT -5. The time now is 06:43 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|