app-admin/tenshi: new revision with tenshi.conf owned by root:root.
authorMichael Orlitzky <mjo@gentoo.org>
Thu, 31 Aug 2017 00:52:49 +0000 (20:52 -0400)
committerMichael Orlitzky <mjo@gentoo.org>
Thu, 31 Aug 2017 00:52:49 +0000 (20:52 -0400)
commit7d56e1b385a02eab7852a3f0677f9f0f63c93df2
treeeb7f3b2da165fedf11a0215ab56a3bc8dff2e6ca
parent14a647be4c461c1f5ecebd383eb4596bda2721d5
app-admin/tenshi: new revision with tenshi.conf owned by root:root.

The tenshi.conf file was owned by the "tenshi" user in previous
revisions. This was open to exploitation because that conf file
contains two important settings:

  1. The UID that the daemon will run as.
  2. The "tail" command to be run on the logfiles.

If the "tenshi" user can write to it, he can specify an arbitrary
command to be run as an arbitrary UID the next time the daemon is
started.

Thanks to Brian De Wolf for noticing the problem.

Package-Manager: Portage-2.3.6, Repoman-2.3.1
app-admin/tenshi/tenshi-0.16-r1.ebuild [moved from app-admin/tenshi/tenshi-0.16.ebuild with 96% similarity]