Displaying 1 result from an estimated 1 matches for "no_suid".
Did you mean:
no_id
2005 Dec 30
5
rssh: root privilege escalation flaw
...ooting to, and
create hard links to SUID binaries within that directory structure, so
by preventing either of these two things, the exploit will be foiled.
System administrators can accomplish this by careful configuration of
filesystem permissions, mount points, and mount options (such as
no_exec, no_suid, etc.). I will not go into details since the far
better solution is to upgrade.
Fix
---
The 2.3.0 release of rssh fixes this problem by forcing the chroot
helper program to re-parse the config file instead of allowing the
chroot home to be specified on the command line. Thus users not
listed ca...