Bug 139339 - tvtime binary installed setuid root
tvtime binary installed setuid root
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: tvtime (Show other bugs)
3
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Ngo Than
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-11-15 08:38 EST by David Balažic
Modified: 2007-11-30 17:10 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-11-16 11:55:15 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Balažic 2004-11-15 08:38:35 EST
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.5)
Gecko/20041107 Firefox/1.0

Description of problem:
The tvtime binary is installed setuid root. Is that wise ?

AFAIK it is because it needs access to /dev/rtc

Can that not be solved in some other way ?

The last thing we need is a remote break-in over TV signals ;-)

Is there really no other way for precise timing but /dev/rtc ?



Version-Release number of selected component (if applicable):
tvtime-0.9.13-1
Comment 1 Ngo Than 2004-11-16 11:14:03 EST
yes, it's needed to set the max-user-freq on /dev/rtc. But I don't see
it's critical because it will be dropped to a user after doing that.
Comment 2 Ngo Than 2004-11-16 11:55:15 EST
in my opinion it's safe by removing setuid root. I will remove it in
next rebuild. Perhaps adding "dev.rtc.max-user-freq = 1024" in
/etc/sysctl.conf.

Note You need to log in before you can comment on or make changes to this bug.