Bug 18637 - Network Management Workstation etc. include Network Server packages
Network Management Workstation etc. include Network Server packages
Status: CLOSED RAWHIDE
Product: Red Hat Linux
Classification: Retired
Component: anaconda (Show other bugs)
7.0
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Brock Organ
Brock Organ
: Security
: 22457 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2000-10-08 09:18 EDT by Pekka Savola
Modified: 2007-04-18 12:29 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-12-08 14:53:17 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Pekka Savola 2000-10-08 09:18:43 EDT
This is a potential security issue.

Classes Network Management Workstation and IPX/Netware(tm) Connectivity
include the class Network Server.  This is a very much misnomer for people 
that specifically choose not to install _any_ 'Server' classes during the selection.

That, in turn, installs the following (plus Classes in Network Workstation):
---
  openssh-server  
  sysstat
  xinetd
  talk-server
  telnet-server
  rusers-server
  rwall-server
  finger-server
  rsh-server
  tftp-server  
  ypserv
---
[ some of these are disabled by default, though -- but nowhere near all ]

These, apart from openssh-server IMO, should _not_ be installed if either
class is selected.  Most of these are just plain unnecessary and contain potential
security issues.

I'd recommend changing the two classes so that they include Networked Workstation 
directly, and perhaps OpenSSH too if you feel like it, but definitely not all of Network Server.

I'd also change '* Server' classes so that they don't install stuff like talk-server and rusers-server 
for all of those by default.  Seriously, The 0.1% who use services like these can install them 
automatically. :-)
Comment 1 Pekka Savola 2000-10-08 09:20:31 EDT
s/automatically/manually/ at the end of the message.
Comment 2 Daniel Roesen 2000-10-08 16:42:17 EDT
I strongly second that.
Comment 3 Michael Fulbright 2000-10-09 11:14:21 EDT
Thank you for the suggestions - I think you have brought up some good points.
Comment 4 Erik Troan 2000-11-17 15:46:18 EST
Fixed
Comment 5 Pekka Savola 2000-11-17 15:58:14 EST
Fixed how?

Removed Network Server dependency from Workstation classes, probably?

But was there a change wrt. installing 99.9% unnecessary stuff like talk-server 
on server configuration?
Comment 6 Erik Troan 2000-11-17 16:10:43 EST
IPX/Network Services was included Network Servers, which was done.

We're still debating how to fix the other bug (which is still open)
Comment 7 Aaron Brown 2000-12-13 14:20:08 EST
Verified as resolved.
Comment 8 Brock Organ 2001-01-10 14:44:44 EST
*** Bug 22457 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.