Bugtraq mailing list archives

Re: BUG? Non-root user can configure traffic shaper (2.2.13) (fwd)


From: alan () LXORGUK UKUU ORG UK (Alan Cox)
Date: Tue, 28 Dec 1999 00:41:45 +0000


Non-root users can change the SPEED of shaped interface. I.e., usual user
can run "shapecfg speed shaper0 XXX" with success result. In my case
non-root user increases speed of shaped interface to my proxy server. Yep,
NO ANY suid's on `which shapecfg`. It's has 0755 permission.


This was reported a while ago and is already fixed in 2.2.14pre. Pick up the
patch from that to drivers/net/shaper.c. It is the only change needed.

Alan


Current thread: