Re: Local users get to play root?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 11/18/2009 07:37 PM, Colin Walters wrote:
On Wed, Nov 18, 2009 at 7:36 PM, Jeff Garzik<jgarzik@xxxxxxxxx>  wrote:

And it ignores that remote exploits are now much easier, because remote
non-root exploit + package install == remote root exploit.

No, the uid needs to have logged in through a physical console.


See references in multiple mails to firefox, pidgin, and any number of other example applications run by a uid logged in through a physical console.

Web browsers -- especially with bin-only flash -- are the most likely vector for remote exploits these days. Far more so than any system daemon.

There are Real Good(tm) reasons why Firefox complains, if your Flash plug-in is out of date, even on Linux...

	Jeff



--
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux