Gentoo Archives: gentoo-dev

From: Chris Gianelloni <wolf31o2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default
Date: Sun, 16 Jul 2006 14:51:57
Message-Id: 1153061127.20077.0.camel@vertigo.twi-31o2.org
In Reply to: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default by Mike Frysinger
1 On Sat, 2006-07-15 at 15:20 -0400, Mike Frysinger wrote:
2 > On Saturday 15 July 2006 13:41, Ned Ludd wrote:
3 > > On Sat, 2006-07-15 at 17:45 +0100, Daniel Drake wrote:
4 > > > The local root exploit-of-the-week would have been unable to run if our
5 > > > users systems had /proc mounted with nosuid and/or noexec
6 > > >
7 > > > It would be worthwhile considering making this a default. What are
8 > > > people's thoughts?
9 > >
10 > > I mailed Mike about this very thing a month ago. Pretty sure it should
11 > > be showing up in an upcoming baselayout. But yeah it's a good idea for
12 > > the nosuid part anyway. Not 100% sure about the noexec part as that
13 > > might break upx which calls /proc/self/exe as part of it's decompresser
14 > > routines.
15 >
16 > this will be in baselayout-1.12.2+
17
18 Great. I'm guessing I should artificially bump 1.12.1 with a revision
19 in my snapshot for 2006.1 or we'll end up not having fixed much.
20
21 --
22 Chris Gianelloni
23 Release Engineering - Strategic Lead
24 x86 Architecture Team
25 Games - Developer
26 Gentoo Linux

Attachments

File name MIME type
signature.asc application/pgp-signature