oss-sec mailing list archives
Re: Re: [Pkg-shadow-devel] subuid security patches for shadow package
From: Sebastian Krahmer <krahmer () suse com>
Date: Mon, 25 Jul 2016 10:39:30 +0200
On Mon, Jul 25, 2016 at 10:03:31AM +0200, Sebastian Krahmer wrote:
On Wed, Jul 20, 2016 at 11:48:52PM +0200, Nicolas François wrote:Hi, The first point looks like a non issue to me. getlogin() is used to differentiate users with the same UID. The result of getlogin() is checked: if it returns a username that do not have the UID returned by getuid(), it will be ignored. Best Regards, -- NekralI agree that its not a severe issue. But its dubious code at best. I couldnt even imagine someone would have usernames with different UID's? Maybe such configs should not be encouraged and potential issues with that discussed. My understanding of secure coding is that getlogin() should not be trusted. Having same username with multiple UIDs is also to be avoided IMHO, since its asking for trouble (I dont know if thats some requirement of LSB or POSIX or so?)
Err, sorry. Shared UID, different name (the other way around, thanks Alex). But then you are open to GID hopping attacks (as also previously pointed out) since you actually _do_ rely on getlogin() trust. Sebastian -- ~ perl self.pl ~ $_='print"\$_=\47$_\47;eval"';eval ~ krahmer () suse com - SuSE Security Team
Current thread:
- subuid security patches for shadow package Sebastian Krahmer (Jul 19)
- Re: subuid security patches for shadow package Sebastian Krahmer (Jul 19)
- Re: subuid security patches for shadow package Eric W. Biederman (Jul 19)
- Re: [Pkg-shadow-devel] subuid security patches for shadow package Nicolas François (Jul 20)
- Re: Re: [Pkg-shadow-devel] subuid security patches for shadow package Salvatore Bonaccorso (Jul 22)
- Re: Re: [Pkg-shadow-devel] subuid security patches for shadow package Sebastian Krahmer (Jul 25)
- Re: Re: [Pkg-shadow-devel] subuid security patches for shadow package Sebastian Krahmer (Jul 25)
- Re: Re: [Pkg-shadow-devel] subuid security patches for shadow package Solar Designer (Jul 25)
- Re: subuid security patches for shadow package Eric W. Biederman (Jul 19)
- Re: subuid security patches for shadow package Sebastian Krahmer (Jul 19)