From kfm-devel Sat Oct 09 14:18:00 1999 From: owner () bugs ! kde ! org (Stephan Kulow) Date: Sat, 09 Oct 1999 14:18:00 +0000 To: kfm-devel Subject: Bug#1956: marked as done (kfmsu2 is insecure) X-MARC-Message: https://marc.info/?l=kfm-devel&m=93947804004679 Your message dated Sat, 9 Oct 1999 16:02:47 +0200 with message-id <19991009160245.F25150@faui08c.informatik.uni-erlangen.de> and subject line closing bug "kfmsu2 is insecure" has caused the attached bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I'm talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Stephan Kulow (administrator, KDE bugs database) Received: (at submit) by bugs.kde.org; 15 Sep 1999 16:59:31 +0000 From m1tca00@frb.gov Wed Sep 15 18:59:31 1999 Received: from fed.frb.gov ([132.200.32.32]:55812 "EHLO fed-ef1.frb.gov") by max.tat.physik.uni-tuebingen.de with ESMTP id ; Wed, 15 Sep 1999 18:59:22 +0200 Received: by fed-ef1.frb.gov; id MAA27354; Wed, 15 Sep 1999 12:58:58 -0400 (EDT) Received: from m1pmdf.frb.gov(192.168.3.38) by fed.frb.gov via smap (V4.2) id xma026823; Wed, 15 Sep 99 12:58:04 -0400 Date: Wed, 15 Sep 1999 12:57:53 -0400 From: Tom Allard Subject: kfmsu2 is insecure To: submit@bugs.kde.org Message-id: <199909151657.MAA21507@bksmx1.FRB.GOV> Organization: Federal Reserve B.O.G. MIME-version: 1.0 Content-type: text/plain; charset=us-ascii X-pgp-key-fingerprint: 10 49 F5 24 F1 D9 A7 D6 DE 14 25 C8 C0 E2 57 9D X-face: U884%sdg]b6S$/.,?^*Qkd{@]V8-^P$"MKrQ2LU9#,OfCS[O)YMw'CMYvk$eG~&D5H)K./( b}!?|^0V:WR]@n\>jy;],w^m8tH*x6M^`s4@^#24nE~d@WQ<+:Pi|X/_@Aj^\pYl[(FzY\k|l2.}4H #%u@>[qapGEy0b!x4k X-Orcpt: rfc822;submit@bugs.kde.org Package: kfm Version: 1.1.2 kfmsu2 calls "xhost +local:", which is insecure. I suggest setting the XAUTHORITY environment for root to that of the user's to securely give root access to the display: Remove "xhost +local:" and change su: su - root -c "XAUTHORITY=$HOME/.Xauthority; DISPLAY=$DISPLAY; \ export XAUTHORITY DISPLAY; $kfm -sw >/dev/null" I am using both Debian Slink and Redhat 6.0 with updates.