[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE-2020-7221: mariadb: possible local mysql to root user exploit in mysql_instal
From:       Matthias Gerstner <mgerstner () suse ! de>
Date:       2020-02-04 13:09:19
Message-ID: 20200204130919.GD11664 () f195 ! suse ! de
[Download RAW message or body]


Hi,

On Tue, Feb 04, 2020 at 01:27:11PM +0100, Solar Designer wrote:
> > I personally suggest the following directory mode instead:
> > 
> > root:mysql  0750 /usr/lib/mysql/plugin/auth_pam_tool_dir
> 
> Why not simply
> 
> root:mysql 04710 /usr/lib/mysql/plugin/auth_pam_tool
> 
> without the directory?  I see only one reason: it's a bigger change
> relative to the current implementation, which is more work now, but
> perhaps this cleanup is worth it longer-term.

yes, exactly. I don't want to diverge too much from what upstream does
at the moment.

When this doesn't matter then your suggestion is the better one and
would be the cleaner approach for upstream to follow.

Cheers

Matthias

["signature.asc" (application/pgp-signature)]

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic