1 |
On Saturday 15 July 2006 13:41, Ned Ludd wrote: |
2 |
> On Sat, 2006-07-15 at 17:45 +0100, Daniel Drake wrote: |
3 |
> > The local root exploit-of-the-week would have been unable to run if our |
4 |
> > users systems had /proc mounted with nosuid and/or noexec |
5 |
> > |
6 |
> > It would be worthwhile considering making this a default. What are |
7 |
> > people's thoughts? |
8 |
> |
9 |
> I mailed Mike about this very thing a month ago. Pretty sure it should |
10 |
> be showing up in an upcoming baselayout. But yeah it's a good idea for |
11 |
> the nosuid part anyway. Not 100% sure about the noexec part as that |
12 |
> might break upx which calls /proc/self/exe as part of it's decompresser |
13 |
> routines. |
14 |
|
15 |
this will be in baselayout-1.12.2+ |
16 |
-mike |