Gentoo Archives: gentoo-dev

From: Wolfram Schlich <wschlich@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] net-mail/mailman-2.1.9-r2: Request for testing
Date: Tue, 27 Nov 2007 01:49:44
Message-Id: 20071127014624.GB16769@bla.fasel.org
In Reply to: Re: [gentoo-dev] net-mail/mailman-2.1.9-r2: Request for testing by Wolfram Schlich
1 * Wolfram Schlich <wschlich@g.o> [2007-11-27 02:31]:
2 > * Wolfram Schlich <wschlich@g.o> [2007-11-27 02:24]:
3 > > * Hanno Böck <hanno@g.o> [2007-11-26 15:39]:
4 > > > [...]
5 > > > So I'd like to unmask it soon. Please, if you're using mailman test it, tell
6 > > > me if it suits your needs or just give me feedback like "worksforme", I
7 > > > actually don't have a clue how many people really use this ebuild.
8 > >
9 > > I get this using hardened-sources with activated grsecurity
10 > > trusted path execution feature:
11 > >
12 > > 2007-11-27 02:15:47 +01:00; alpha; kern.alert; kernel: grsec: From 127.0.0.6: \
13 > > denied untrusted exec of /usr/lib/mailman/bin/mmsitepass by \
14 > > /bin/bash[bash:14178] uid/euid:280/280 gid/egid:280/280, \
15 > > parent /bin/bash[bash:14173] uid/euid:280/280 gid/egid:280/280
16 > >
17 > > That's because /usr/lib/mailman/bin/ is group-writable.
18 >
19 > Ok, that's not true :]
20 >
21 > Using this configuration...
22 > --8<--
23 > CONFIG_GRKERNSEC_TPE=y
24 > # CONFIG_GRKERNSEC_TPE_ALL is not set
25 > CONFIG_GRKERNSEC_TPE_INVERT=y
26 > CONFIG_GRKERNSEC_TPE_GID=1005
27 > --8<--
28 > ...I have to add 'mailman' to group 1005.
29
30 Ok, it get's worse: for the mailman webinterface, I'd have to add
31 'apache' to group 1005 as well, opening up even bigger holes.
32 No way! So, emerge -C mailman, that is :(
33 Too bad.
34 --
35 Regards,
36 Wolfram Schlich <wschlich@g.o>
37 Gentoo Linux * http://dev.gentoo.org/~wschlich/
38 --
39 gentoo-dev@g.o mailing list