Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Ensure proper user rights for Wine
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Gentree
Watchman
Watchman


Joined: 01 Jul 2003
Posts: 5350
Location: France, Old Europe

PostPosted: Sun Nov 20, 2005 9:22 pm    Post subject: Ensure proper user rights for Wine Reply with quote

A potentially nasty bug has just been revealed on wine-devel mailing list.

If the user under which Wine is run is a member of disk or wheel groups , winecfg will destroy the MBR!

Since Wine will be running windows software this issue simply underlines the need to make sure that that user is sufficiently well shackled not to do any damage if he get's some malitious code (or a bug in wine).

8)
_________________
Linux, because I'd rather own a free OS than steal one that's not worth paying for.
Gentoo because I'm a masochist
AthlonXP-M on A7N8X. Portage ~x86
Back to top
View user's profile Send private message
Voltago
Advocate
Advocate


Joined: 02 Sep 2003
Posts: 2593
Location: userland

PostPosted: Sun Nov 20, 2005 9:34 pm    Post subject: Reply with quote

How can a wheel- and non-disk-user even touch the MBR?
Back to top
View user's profile Send private message
Gentree
Watchman
Watchman


Joined: 01 Jul 2003
Posts: 5350
Location: France, Old Europe

PostPosted: Sun Nov 20, 2005 9:54 pm    Post subject: Reply with quote

Dont know , what services does the wheel group provide?

from the wine-devel ML:
Quote:

> >> > Le dimanche 20 novembre 2005 à 18:57 +0100, wino@piments.com a
écrit :
> >> > > On Sun, 20 Nov 2005 18:33:53 +0100, Oliver Stieber
> >> > > <oliver_stieber@yahoo.co.uk> wrote:
> >> > >
> >> > > > I've just tried at it appears to have wiped my MBR logged in
as
> >> a normal
> >> > > > User in wheel group.
> >> > > > If this is the problem then I purchsed a new drive because of
it
> >> last
> >> > > > month.
> >> > > > Oliver.

_________________
Linux, because I'd rather own a free OS than steal one that's not worth paying for.
Gentoo because I'm a masochist
AthlonXP-M on A7N8X. Portage ~x86
Back to top
View user's profile Send private message
Voltago
Advocate
Advocate


Joined: 02 Sep 2003
Posts: 2593
Location: userland

PostPosted: Sun Nov 20, 2005 10:05 pm    Post subject: Reply with quote

On a standard Gentoo system, wheel users are allowed to use 'su'.
Btw, link: http://www.winehq.org/pipermail/wine-devel/2005-November/042554.html
Back to top
View user's profile Send private message
Da Fox
Guru
Guru


Joined: 06 Jul 2005
Posts: 342

PostPosted: Sun Nov 20, 2005 10:19 pm    Post subject: Reply with quote

but wouldn't you still need to give in you root password for 'su'?
_________________
"Man fears the darkness, and so he scrapes away at the edges of it with fire."
- Rei Ayanami

JGBE, a Java based GameBoy Emulator
Back to top
View user's profile Send private message
PaulBredbury
Watchman
Watchman


Joined: 14 Jul 2005
Posts: 7310

PostPosted: Sun Nov 20, 2005 10:22 pm    Post subject: Reply with quote

Don't run wine as root (pretty obvious), and don't add a user to the "disk" group to give him the ability to destroy the boot sector :)
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum