i386/69264: security, regular user able to browse root home folder

Ara Avvali ara at avvali.com
Sun Jul 18 20:40:24 PDT 2004


>Number:         69264
>Category:       i386
>Synopsis:       security, regular user able to browse root home folder
>Confidential:   no
>Severity:       critical
>Priority:       high
>Responsible:    freebsd-i386
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Mon Jul 19 03:40:24 GMT 2004
>Closed-Date:
>Last-Modified:
>Originator:     Ara Avvali
>Release:        4-10
>Organization:
Personal
>Environment:
%uname -a
FreeBSD FreeBSD.local 4.10-RELEASE FreeBSD 4.10-RELEASE #0: Tue May 25 22:47:12 GMT 2004     root at perseus.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  i386
%


>Description:
      hi
i just noticed something crazy that i have to mention to you guys
when i login as regular user to gnome, it gives me the ability to browse through root's home folder and desktop, although i am a regular user
i don't think this is some thing normal and have to let you guys know
Thank you
>How-To-Repeat:
      
>Fix:
      
>Release-Note:
>Audit-Trail:
>Unformatted:


More information about the freebsd-i386 mailing list