Bug#571323: [smbfs] missing sticky bit on /sbin/*mount.cifs

2010-02-27 Thread Baggett Jonas
Hi, It is actually a temporary mesure until mount.cifs will be fixed to be safe when it is setuid, see : http://lists.samba.org/archive/linux-cifs-client/2010-February/005558.html As I understand, the threat is a local root exploit. But I think that a lot of people don't expect that somebody

Bug#571323: [smbfs] missing sticky bit on /sbin/*mount.cifs

2010-02-27 Thread Steve Langasek
On Sat, Feb 27, 2010 at 09:20:14AM +0100, Baggett Jonas wrote: It is actually a temporary mesure until mount.cifs will be fixed to be safe when it is setuid No, it is not. The temporary measure refers to the fact that it is now *impossible* to run mount.cifs suid-root; even when that is

Bug#571323: [smbfs] missing sticky bit on /sbin/*mount.cifs

2010-02-25 Thread Guy Roussin
Package: smbfs Version: 2:3.4.5~dfsg-2 Severity: normal --- Please enter the report below this line. --- Hi, No more sticky bit on /sbin/mount.cifs and /sbin/umount.cifs we have script to mount shares on user host. This is the error (a bit crypted) : mount error(1): Operation not permitted