From owner-freebsd-ports-bugs@FreeBSD.ORG Wed Jul 18 12:10:08 2007 Return-Path: X-Original-To: freebsd-ports-bugs@hub.freebsd.org Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 35A1D16A404 for ; Wed, 18 Jul 2007 12:10:08 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freebsd.org [69.147.83.40]) by mx1.freebsd.org (Postfix) with ESMTP id 0582A13C4A6 for ; Wed, 18 Jul 2007 12:10:08 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.1/8.14.1) with ESMTP id l6ICA7ts026281 for ; Wed, 18 Jul 2007 12:10:07 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.1/8.14.1/Submit) id l6ICA7lW026280; Wed, 18 Jul 2007 12:10:07 GMT (envelope-from gnats) Date: Wed, 18 Jul 2007 12:10:07 GMT Message-Id: <200707181210.l6ICA7lW026280@freefall.freebsd.org> To: freebsd-ports-bugs@FreeBSD.org From: Cristian KLEIN Cc: Subject: Re: ports/112754: VERY SERIOUS security bug in sysutils/eject X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Cristian KLEIN List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 18 Jul 2007 12:10:08 -0000 The following reply was made to PR ports/112754; it has been noted by GNATS. From: Cristian KLEIN To: bug-followup@FreeBSD.org, ighighi@gmail.com Cc: Subject: Re: ports/112754: VERY SERIOUS security bug in sysutils/eject Date: Wed, 18 Jul 2007 15:01:17 +0300 Besides the change suggested by the reporter, I would also recommend the following pkg-message: NOTE: This port is no longer installed with SETUID, because it allows non-privileged users to unmount a filesystem. To enable your users to eject the CD-ROM, install security/sudo and enter the following line in /usr/local/etc/sudoers: %users ALL=/usr/local/sbin/eject /dev/acd0