Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 3 Apr 2015 12:31:58 +0200
From: u-wsnj@...ey.se
To: musl@...ts.openwall.com
Subject: [OT] setuid (Re: Busybox on musl is affected by CVE-2015-1817)

On Fri, Apr 03, 2015 at 11:51:58AM +0700, Рысь wrote:
> Unix credentials were always somewhat limited

Exactly.

Set*id was created to complement the poor authorization means in the
kernel (acls limited to three permissions and crippled to exactly
three group-like entries with restricted semantics, for implementation
efficiency reasons).

It (set*id) is a very powerful, general and wide reaching tool intended in
contrast for special and varying situations which need specific treatment,
that's why it needs extreme skills and care at every use.

This does not scale.

Rune

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.