Gentoo Archives: gentoo-dev

From: Ned Ludd <solar@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default
Date: Sat, 15 Jul 2006 17:46:00
Message-Id: 1152985304.24093.16.camel@localhost
In Reply to: [gentoo-dev] Making procfs mount as nosuid,noexec by default by Daniel Drake
1 On Sat, 2006-07-15 at 17:45 +0100, Daniel Drake wrote:
2 > Hi,
3 >
4 > The local root exploit-of-the-week would have been unable to run if our
5 > users systems had /proc mounted with nosuid and/or noexec
6 >
7 > It would be worthwhile considering making this a default. What are
8 > people's thoughts?
9
10 I mailed Mike about this very thing a month ago. Pretty sure it should
11 be showing up in an upcoming baselayout. But yeah it's a good idea for
12 the nosuid part anyway. Not 100% sure about the noexec part as that
13 might break upx which calls /proc/self/exe as part of it's decompresser
14 routines.
15
16 --
17 Ned Ludd <solar@g.o>
18 Gentoo Linux
19
20 --
21 gentoo-dev@g.o mailing list

Replies