1 |
* Wolfram Schlich <wschlich@g.o> [2007-11-27 02:31]: |
2 |
> * Wolfram Schlich <wschlich@g.o> [2007-11-27 02:24]: |
3 |
> > * Hanno Böck <hanno@g.o> [2007-11-26 15:39]: |
4 |
> > > [...] |
5 |
> > > So I'd like to unmask it soon. Please, if you're using mailman test it, tell |
6 |
> > > me if it suits your needs or just give me feedback like "worksforme", I |
7 |
> > > actually don't have a clue how many people really use this ebuild. |
8 |
> > |
9 |
> > I get this using hardened-sources with activated grsecurity |
10 |
> > trusted path execution feature: |
11 |
> > |
12 |
> > 2007-11-27 02:15:47 +01:00; alpha; kern.alert; kernel: grsec: From 127.0.0.6: \ |
13 |
> > denied untrusted exec of /usr/lib/mailman/bin/mmsitepass by \ |
14 |
> > /bin/bash[bash:14178] uid/euid:280/280 gid/egid:280/280, \ |
15 |
> > parent /bin/bash[bash:14173] uid/euid:280/280 gid/egid:280/280 |
16 |
> > |
17 |
> > That's because /usr/lib/mailman/bin/ is group-writable. |
18 |
> |
19 |
> Ok, that's not true :] |
20 |
> |
21 |
> Using this configuration... |
22 |
> --8<-- |
23 |
> CONFIG_GRKERNSEC_TPE=y |
24 |
> # CONFIG_GRKERNSEC_TPE_ALL is not set |
25 |
> CONFIG_GRKERNSEC_TPE_INVERT=y |
26 |
> CONFIG_GRKERNSEC_TPE_GID=1005 |
27 |
> --8<-- |
28 |
> ...I have to add 'mailman' to group 1005. |
29 |
|
30 |
Ok, it get's worse: for the mailman webinterface, I'd have to add |
31 |
'apache' to group 1005 as well, opening up even bigger holes. |
32 |
No way! So, emerge -C mailman, that is :( |
33 |
Too bad. |
34 |
-- |
35 |
Regards, |
36 |
Wolfram Schlich <wschlich@g.o> |
37 |
Gentoo Linux * http://dev.gentoo.org/~wschlich/ |
38 |
-- |
39 |
gentoo-dev@g.o mailing list |