Gentoo Archives: gentoo-dev

From: Mike Frysinger <vapier@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default
Date: Sat, 15 Jul 2006 19:25:15
Message-Id: 200607151520.39867.vapier@gentoo.org
In Reply to: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default by Ned Ludd
1 On Saturday 15 July 2006 13:41, Ned Ludd wrote:
2 > On Sat, 2006-07-15 at 17:45 +0100, Daniel Drake wrote:
3 > > The local root exploit-of-the-week would have been unable to run if our
4 > > users systems had /proc mounted with nosuid and/or noexec
5 > >
6 > > It would be worthwhile considering making this a default. What are
7 > > people's thoughts?
8 >
9 > I mailed Mike about this very thing a month ago. Pretty sure it should
10 > be showing up in an upcoming baselayout. But yeah it's a good idea for
11 > the nosuid part anyway. Not 100% sure about the noexec part as that
12 > might break upx which calls /proc/self/exe as part of it's decompresser
13 > routines.
14
15 this will be in baselayout-1.12.2+
16 -mike

Replies

Subject Author
Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default Chris Gianelloni <wolf31o2@g.o>