Описание
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
trousers | fixed | 0.3.15-0.1 | package |
Примечания
https://bugzilla.suse.com/show_bug.cgi?id=1164472
https://sourceforge.net/p/trousers/mailman/message/37015817/
https://www.openwall.com/lists/oss-security/2020/08/14/1
In Debian, tcsd gets started under the tss user
Связанные уязвимости
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.