Bug 139339 - tvtime binary installed setuid root
Summary: tvtime binary installed setuid root
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: tvtime (Show other bugs)
(Show other bugs)
Version: 3
Hardware: i386 Linux
medium
medium
Target Milestone: ---
Assignee: Ngo Than
QA Contact:
URL:
Whiteboard:
Keywords:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2004-11-15 13:38 UTC by David Balažic
Modified: 2007-11-30 22:10 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-11-16 16:55:15 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description David Balažic 2004-11-15 13:38:35 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.5)
Gecko/20041107 Firefox/1.0

Description of problem:
The tvtime binary is installed setuid root. Is that wise ?

AFAIK it is because it needs access to /dev/rtc

Can that not be solved in some other way ?

The last thing we need is a remote break-in over TV signals ;-)

Is there really no other way for precise timing but /dev/rtc ?



Version-Release number of selected component (if applicable):
tvtime-0.9.13-1

Comment 1 Ngo Than 2004-11-16 16:14:03 UTC
yes, it's needed to set the max-user-freq on /dev/rtc. But I don't see
it's critical because it will be dropped to a user after doing that.

Comment 2 Ngo Than 2004-11-16 16:55:15 UTC
in my opinion it's safe by removing setuid root. I will remove it in
next rebuild. Perhaps adding "dev.rtc.max-user-freq = 1024" in
/etc/sysctl.conf.


Note You need to log in before you can comment on or make changes to this bug.