Bug 182352

Summary: HAL allows non-privileged console user to circumvent system policy
Product: [Fedora] Fedora Reporter: David Zeuthen <davidz>
Component: halAssignee: John (J5) Palmieri <johnp>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: jkeck, mclasen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 0.5.7-1 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-02-25 01:56:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 150222    

Description David Zeuthen 2006-02-21 23:13:05 UTC
Description of problem:

HAL allows non-privileged console user to circumvent system policy by allowing
mounting of devices that the administrator put in /etc/fstab

Expected results:

HAL should refuse Mount() methods on devices specifically listed in /etc/fstab.

Additional info:

I've got a fix for this in HAL CVS. As I'm the upstream developer I also urge
upgrading to a new release for FC5Final rather soon as other important (though
not security critical) bugs have been fixed. I will do a hal 0.5.7 release later
this week.

I am marking this as a FC5 blocker bug.