Menu

#18 "Forbid" to run JTAG tools with suid root

0.10
closed-fixed
None
5
2007-11-30
2007-11-25
No

The JTAG tools can be used to gain superuser access to the system. The most basic way to do this would be to use the "shell" command.

It would be a large security hole to install the tools so that arbitrary users can run them with superuser rights (suid root); on the other hand probably a number of people might be tempted to do so in order to work around "permission denied" problems when trying to access a cable over parport or usb.

Running the tools as root is okay, but becoming root by just using the tools has to be impossible.

Discussion

  • Kolja Waschk

    Kolja Waschk - 2007-11-28

    Logged In: YES
    user_id=478715
    Originator: YES

    Added a check in #801.

     
  • Kolja Waschk

    Kolja Waschk - 2007-11-28
    • assigned_to: nobody --> kawk
    • status: open --> closed
     
  • Kolja Waschk

    Kolja Waschk - 2007-11-30
    • status: closed --> closed-fixed
     
  • Kolja Waschk

    Kolja Waschk - 2017-02-12
    • Group: --> 0.10
     

Log in to post a comment.

MongoDB Logo MongoDB
Gen AI apps are built with MongoDB Atlas
Atlas offers built-in vector search and global availability across 125+ regions. Start building AI apps faster, all in one place.