open and euid security flaw in 5.0-Current?

From: Killing (killing_at_barrysworld.com)
Date: 05/17/03

  • Next message: Killing: "Re: open and euid security flaw in 5.0-Current?"
    To: <freebsd-hackers@freebsd.org>, <freebsd-security@freebsd.org>
    Date: Sat, 17 May 2003 03:46:15 +0100
    
    

    On a FreeBSD 5.0 the behaviour of screen when connecting to other
    users sessions have changed. Previously:
    1. login as userA start a screen as userA and disconnect
    2. login as root su - userA "screen -r"
    3. result failure as userA cant access the ttyX with such a message
    Current:
    1. login as userA start a screen as userA and disconnect
    2. login as root su - userA "screen -r"
    3. result failure as userA cant access the ttyX but no message

    After looking around in screen's code I found that after doing a
    seteuid( userA ) an open on root's terminal is still succeseding.

    Surely this is a problem as when running euid userA there should
    be no access to ruid's files?

        Steve / K

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Killing: "Re: open and euid security flaw in 5.0-Current?"

    Relevant Pages

    • Re: Simultaneous Users - Remote Connection and Desktop User
      ... I connect from another machine to my computer using UserA login. ... with UserB login, my UserA connection is dropped off. ... concurrent connection - period, local and/or remote. ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: Simultaneous Users - Remote Connection and Desktop User
      ... I connect from another machine to my computer using UserA login. ... any of my family members logs into the computer directly with UserB login, ... Educate your family members not to break running sessions. ...
      (microsoft.public.windowsxp.work_remotely)
    • funny characters in Task Scheduler
      ... I've created a few scheduled backup jobs, using an user account (eg. UserA) ... with Backup Operator rights locally. ... After a few weeks, when I login as the UserA to view the Task Scheduler, the ...
      (microsoft.public.windows.server.general)
    • Remote login access
      ... We have a unique situation here - we don't want people to login ... directly to a user-id, say userA. ... personal IDs and then su - to userA. ...
      (comp.security.ssh)
    • Strange problem Read Only for same user in difference workstation
      ... I login in as USERA in workstation A. When I open a Office file in SBS2003, ...
      (microsoft.public.windows.server.sbs)