Bug 74297 - security/sudoscript to 2.1.2; fixes security bug
Summary: security/sudoscript to 2.1.2; fixes security bug
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: freebsd-ports-bugs (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-11-23 16:50 UTC by Howard Owen
Modified: 2004-11-24 05:44 UTC (History)
0 users

See Also:


Attachments
portpatch (5.08 KB, text/plain)
2004-11-23 16:50 UTC, Howard Owen
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Howard Owen 2004-11-23 16:50:20 UTC
Version 2.1.2 of sudoscript closes a hole in which a member of the 
"ssers" group, in use when non-root access is enabled by sudoscript,
can send a HUP signal to any process on the system.

This update changes the signal used by sudoscriptd from HUP to
WINCH. The latter is ignored by most process whereas the former
is not. If sudoscript is used to enable root access only, then this
bug doesn't bite, since the root enabled user can do lots more mischeif
without signaling arbitrary processes.

How-To-Repeat: I could tell you, but then I'd have to shoot myself. 8)
Comment 1 Daichi GOTO freebsd_committer freebsd_triage 2004-11-24 05:44:24 UTC
State Changed
From-To: open->closed

Committed. Thanks!