i386/69264: security, regular user able to browse root home folder
Ara Avvali
ara at avvali.com
Sun Jul 18 20:40:24 PDT 2004
>Number: 69264
>Category: i386
>Synopsis: security, regular user able to browse root home folder
>Confidential: no
>Severity: critical
>Priority: high
>Responsible: freebsd-i386
>State: open
>Quarter:
>Keywords:
>Date-Required:
>Class: sw-bug
>Submitter-Id: current-users
>Arrival-Date: Mon Jul 19 03:40:24 GMT 2004
>Closed-Date:
>Last-Modified:
>Originator: Ara Avvali
>Release: 4-10
>Organization:
Personal
>Environment:
%uname -a
FreeBSD FreeBSD.local 4.10-RELEASE FreeBSD 4.10-RELEASE #0: Tue May 25 22:47:12 GMT 2004 root at perseus.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC i386
%
>Description:
hi
i just noticed something crazy that i have to mention to you guys
when i login as regular user to gnome, it gives me the ability to browse through root's home folder and desktop, although i am a regular user
i don't think this is some thing normal and have to let you guys know
Thank you
>How-To-Repeat:
>Fix:
>Release-Note:
>Audit-Trail:
>Unformatted:
More information about the freebsd-i386
mailing list