Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Cc: Etaoin Shrdlu <shrdlu@×××××××××××××.org>
Subject: Re: [gentoo-user] sudo in kernel config ?
Date: Sat, 11 Sep 2010 20:49:29
Message-Id: 201009112249.03770.alan.mckinnon@gmail.com
In Reply to: Re: [gentoo-user] sudo in kernel config ? by Etaoin Shrdlu
1 Apparently, though unproven, at 22:28 on Saturday 11 September 2010, Etaoin
2 Shrdlu did opine thusly:
3
4 > On Sat, 11 Sep 2010 15:35:58 -0500 Dale <rdalek1967@×××××.com> wrote:
5 > > If they are accessible by a user, couldn't a user then edit or add
6 > > something that would then cause a security problem? If they can edit
7 > > them and no one know it, then root comes along and builds a shiney new
8 > > kernel with a really nice security hole.
9 >
10 > This was actually a potential risk once upon a time:
11 >
12 > http://attrition.org/security/advisory/gobbles/GOBBLES-16.txt
13
14 More like an actual risk all the time. Which is why:
15
16 # ls -al /usr/src/
17 total 2
18 drwxr-xr-x 3 root root 136 2010-09-01 11:41 .
19 drwxr-xr-x 17 root root 480 2010-08-23 01:44 ..
20 -rw-r--r-- 1 root root 0 2008-06-17 19:37 .keep
21 lrwxrwxrwx 1 root root 18 2010-09-01 11:30 linux -> linux-2.6.35-ck-r2
22 drwxr-xr-x 24 root root 1584 2010-09-01 02:12 linux-2.6.35-ck-r2
23
24
25
26 --
27 alan dot mckinnon at gmail dot com