Bug 139339 - tvtime binary installed setuid root
Summary: tvtime binary installed setuid root
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: tvtime
Version: 3
Hardware: i386
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Than Ngo
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-11-15 13:38 UTC by David Balažic
Modified: 2007-11-30 22:10 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2004-11-16 16:55:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description David Balažic 2004-11-15 13:38:35 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.5)
Gecko/20041107 Firefox/1.0

Description of problem:
The tvtime binary is installed setuid root. Is that wise ?

AFAIK it is because it needs access to /dev/rtc

Can that not be solved in some other way ?

The last thing we need is a remote break-in over TV signals ;-)

Is there really no other way for precise timing but /dev/rtc ?



Version-Release number of selected component (if applicable):
tvtime-0.9.13-1

Comment 1 Than Ngo 2004-11-16 16:14:03 UTC
yes, it's needed to set the max-user-freq on /dev/rtc. But I don't see
it's critical because it will be dropped to a user after doing that.

Comment 2 Than Ngo 2004-11-16 16:55:15 UTC
in my opinion it's safe by removing setuid root. I will remove it in
next rebuild. Perhaps adding "dev.rtc.max-user-freq = 1024" in
/etc/sysctl.conf.


Note You need to log in before you can comment on or make changes to this bug.