Gentoo Archives: gentoo-user

From: Ian Zimmerman <itz@×××××××.net>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: setuid/setgid binaries, man-db security fix
Date: Tue, 13 Dec 2016 23:30:09
Message-Id: 20161213230742.14389.12E87AD0@matica.foolinux.mooo.com
In Reply to: Re: [gentoo-user] setuid/setgid binaries, man-db security fix by Jeremi Piotrowski
1 On 2016-12-13 08:20, Jeremi Piotrowski wrote:
2
3 > > More generally, I'm wondering about set*id binaries in gentoo. If I
4 > > don't want/need the particular feature thus provided, can I simply
5 > > turn off the set*id bit?
6 >
7 > Most of the time packages will not work correctly (as defined by
8 > upstream) and will require you to run them as root explicitly
9 > (e.g. through sudo).
10
11 Returning to the special case of man-db package, both man and mandb seem
12 to run fine as normal non-suid binaries (after I also changed the perms
13 on /var/cache/man to the normal root:root, 644/755).
14
15 I reported the bug:
16
17 https://bugs.gentoo.org/show_bug.cgi?id=602588
18
19 --
20 Please *no* private Cc: on mailing lists and newsgroups
21 Personal signed mail: please _encrypt_ and sign
22 Don't clear-text sign: http://cr.yp.to/smtp/8bitmime.html

Replies

Subject Author
Re: [gentoo-user] Re: setuid/setgid binaries, man-db security fix Miroslav Rovis <miro.rovis@××××××××××××××.hr>