Re: Local users get to play root?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 11/18/2009 02:10 PM, Seth Vidal wrote:
> 
> 
> On Wed, 18 Nov 2009, Konstantin Ryabitsev wrote:
> 
>> 2009/11/18 Casey Dahlin <cdahlin@xxxxxxxxxx>:
>>> On 11/18/2009 01:22 PM, James Antill wrote:
>>>>
>>>> 3. Are there any attacks due to disk space used? Eg. If /var is low² I
>>>> can probably install enough pkgs to make logging stop.
>>>>
>>>
>>> I'm betting there's still enough systems out there without enough
>>> space in /usr for the entire package set.
>>
>> That's kind of a silly exercise in what-ifs. The default anaconda
>> partition scheme is /boot, <swap>, and /. If someone wanted to fill up
>> the disk, they can just write to /tmp on a default install.
> 
> well - except for the 5% reserved for root :)
> 
> -sv
> 

Which isn't safe from this since ultimately its root doing the install on the unprivileged user's behalf.

--CJD

-- 
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux