Re: Why procmail port installed with SUID root?

From: Cliff Sarginson (csfbsd@raggedclown.net)
Date: 02/25/02


Date: Mon, 25 Feb 2002 16:11:02 +0100
From: Cliff Sarginson <csfbsd@raggedclown.net>
To: freebsd-security@FreeBSD.ORG

On Mon, Feb 25, 2002 at 10:43:32AM +0300, Andrey V. Pevnev wrote:
> Hello!
>
> Does anybody knows why procmail-3.22 port installed with SUID root by
> default? I'am using it as MDA from sendmail-8.12.2
> (FEATURE(`local_procmail')), and it works fine without SUID (I've
> chmod'ed it to 555).
> I think that it's better to install it without SUID by default (as
> mail.local) to make system more secure.
>
    -d recipient ...
            This turns on explicit delivery mode, delivery will
            be to the local user recipient. This, of course,
            only is possible if procmail has root privileges (or
            if procmail is already running with the recipient's
            euid and egid). Procmail will setuid to the intended
            recipients and delivers the mail as if it were
            invoked by the recipient with no arguments (i.e., if
            no rcfile is found, delivery is like ordinary mail).
            This option is incompatible with -p.

-- 
Regards
   Cliff Sarginson -- <csfbsd@raggedclown.net>
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Why procmail port installed with SUID root?
    ... Does anybody knows why procmail-3.22 port installed with SUID root by ... I'am using it as MDA from sendmail-8.12.2 ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: FreeBSD 4.3 local root PREVENTIONS
    ... >> need suid as nosuid? ... > Yes, it is a better practice, but in this case it doesn't help. ... > bash-2.03$ mount | grep tmp ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: SUID program removal
    ... Make suid programs executable by this group. ... Here a list I have hanging around from an unpatched RedHat install (but ... only required to be suid root if you want regular users ... only root needs to change password expiration. ...
    (Focus-Linux)
  • Re: fedora-list Digest, Vol 1, Issue 1394
    ... Ditch use of kppp and use wvdial - you can use a suid perl script to ... then an suid root script to call wvdial is ... > I chose Power Desktop Installation and a decent user-oriented installation ...
    (Fedora)
  • Re: [Full-Disclosure] flames security group start to play , yet another vuln found (rustymemory and
    ... You shouldn't have much on your system that is SUID root. ... >>of flames security group. ... >>Full-Disclosure - We believe in it. ...
    (Full-Disclosure)

Quantcast