[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#25847: general: Several security questions



On Mon, Jul 09, 2001 at 06:49:54PM +0100, Colin Watson wrote:
> 
> They're root:root mode 0600 on my system, but I'm running mingettys.
> Anybody?

getty in woody and potato changes the permissions to 622.  mingetty
correctly changes them to 0600.

> > Is it ok that anybody can write anything to any
> > other tty (/dev/tty7-63) (fake log messages on /dev/tty8 come in mind) ?
> 
> If you use a tty for logging, you should probably restrict its
> permissions ... your changes should be preserved.

this is a more serious bug then that, it was fixed but is now unfixed
(i just rm -fed all my tty[0-9]* devices and reran MADEDEV console,
all ttys were created 0666).  bug#77168

makedev (2.3.1-48) unstable; urgency=low

  * tighten up permissions on /dev/tty[0-XX] and /dev/kbd, closes: #77168

 -- Bdale Garbee <bdale@gag.com>  Sat, 25 Nov 2000 09:45:42 -0700


> If #2 is really done, and if #6 is the same for gettys as for mingettys,
> then all of the other concerns seem to have been addressed by now. Can
> we close this bug? Otherwise we should reassign it to whichever
> package(s) still have problems.

getty should be fixed, and makedev should refix bug#77168

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgpKsWrbfCYqB.pgp
Description: PGP signature


Reply to: