LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-03-2006, 02:29 AM   #1
TomaCzar
Member
 
Registered: Dec 2003
Location: Roc City (Rochester-NY)
Distribution: Slacker 4 Life
Posts: 125

Rep: Reputation: 15
X Windows Systems allows execute as root


Did anyone else see this??:

http://news.yahoo.com/s/zd/20060502/tc_zd/177195

I just stumbled upon it, I would think this would be posted just about everywhere you look (linux-wise). Am I missing something??
 
Old 05-03-2006, 03:02 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by TomaCzar
Did anyone else see this??:

http://news.yahoo.com/s/zd/20060502/tc_zd/177195

I just stumbled upon it, I would think this would be posted just about everywhere you look (linux-wise). Am I missing something??
no, you're not missing anything...

it's not the first security bug in x11, and it won't be the last...

anyways, here's the patch:

for v6.8.2: http://xorg.freedesktop.org/releases...006-1526.patch

for v6.9.0: http://xorg.freedesktop.org/releases...9.0-mitri.diff

for v7.0: http://xorg.freedesktop.org/releases...0.x-mitri.diff

Last edited by win32sux; 05-03-2006 at 03:14 AM.
 
Old 05-03-2006, 11:06 AM   #3
TomaCzar
Member
 
Registered: Dec 2003
Location: Roc City (Rochester-NY)
Distribution: Slacker 4 Life
Posts: 125

Original Poster
Rep: Reputation: 15
No, not the first bug, but due to the massive use of X11 on *nix machines (moreso than any other app?!) and the seriousness of the vulnerability I wasn't expecting to just happen across it while trolling the net.
 
Old 05-03-2006, 12:54 PM   #4
geeman2.0
Member
 
Registered: Feb 2005
Location: Ontario, Canada
Distribution: Gentoo, Slackware
Posts: 345

Rep: Reputation: 30
Most security exploits are published to the net to inform the users.
The users can then either download a patch if available, or switch to a different version where the exploit doesn't exist, etc...

If they didn't publish the exploits then people would ignorantly continue using vulnerable software while wily crackers slip into their systems.
 
Old 05-03-2006, 01:30 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by TomaCzar
No, not the first bug, but due to the massive use of X11 on *nix machines (moreso than any other app?!) and the seriousness of the vulnerability I wasn't expecting to just happen across it while trolling the net.
i actually saw the news published on tons of websites - i guess it depends on one's surfing habits... either way, it's not a highly critical issue IMHO (AFAIK to exploit it you'd have to be authorized to connect to the X server)... BTW, it should be noted that the patch fixes two separate issues: one is the parenthesis issue found by coverity (who are getting great publicity from this, BTW), and the other is a single-character typo in the same file (an ampersand instead of an asterisk)...
 
Old 05-03-2006, 09:16 PM   #6
taylor_venable
Member
 
Registered: Jun 2005
Location: Indiana, USA
Distribution: OpenBSD, Ubuntu
Posts: 892

Rep: Reputation: 43
It's kinda funny to me, since X is such a large and very complex piece of software, that the only people I've heard of running privilege separation and drops on X are the OpenBSD folks. We all know they're a paranoid bunch, and the world (and my servers) are better for it. But has anybody else made the X server run as a non-privileged user?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Systems hangs on Logout from root. duffmckagan Debian 2 11-11-2005 04:31 AM
execute as root tidasu Linux - Newbie 4 08-27-2004 05:25 PM
Root can execute programs lawrencegoodman Linux - Newbie 11 01-28-2004 07:42 AM
execute from root raysr Linux - Newbie 3 12-09-2003 01:41 AM
execute as root ? porous Linux - General 5 10-18-2003 05:30 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration