POV-Ray : Newsgroups : povray.unix : Linux POV-Ray security warning : Re: Linux POV-Ray security warning Server Time
28 Jul 2024 18:27:32 EDT (-0400)
  Re: Linux POV-Ray security warning  
From: Mark Gordon
Date: 26 Nov 1999 08:20:01
Message: <383E88DA.7939A8AD@mailbag.com>
Ralf Muschall wrote:
> 
> Mark Gordon wrote:
> 
> > recommending people change it so that it can only be run by root.
> 
> How much will this help?
> If you receive an evil scene, you either run it with the suid
> version, or you su manually and run it as root. In both cases,
> the same harm will be done.
> 
> The only difference is to avoid attacks by the user himself,
> which is hard anyway if he has physical access to the machine.
> 
> Ralf

The real risk is that someone should get access to a user account on
your machine and use this exploit to parlay it into root access. 
Similarly, if there are several users on your machine, one such user
could potentially use this to gain root access.

If you're the only person who uses your machine, and you're not worried
about possible remote exploits, it's not such a big deal.

-Mark Gordon


Post a reply to this message

Copyright 2003-2023 Persistence of Vision Raytracer Pty. Ltd.