Radix cross Linux

The main Radix cross Linux repository contains the build scripts of packages, which have the most complete and common functionality for desktop machines

452 Commits   2 Branches   1 Tag
Index: README
===================================================================
--- README	(nonexistent)
+++ README	(revision 5)
@@ -0,0 +1,24 @@
+
+/* begin *
+
+   shadow-4.8.1-short-hostname.patch - login: display short hostname
+
+   shadow-4.8.1-CVE-2005-4890.patch:
+   ================================
+     From 0f6a809b7c4c9a8f4adb5b25808dd68000e17aa2 Mon Sep 17 00:00:00 2001
+     From: mancha <mancha1@hush.com>
+     Date: Wed, 04 Dec 2013
+     Subject: restrict "su -c" only when callee is not root
+
+     Shadow 4.1.5 addressed a tty-hijacking vulnerability in "su -c"
+     (CVE-2005-4890) by detaching the controlling terminal in the non-PAM
+     case via a TIOCNOTTY request.
+
+     Bi-directional protection is excessive and breaks a commonly-used
+     methods for privilege escalation on non-PAM systems (e.g. xterm -e 
+     /bin/su -s /bin/bash -c /bin/bash myscript).
+
+     This patch relaxes the restriction and only detaches the controlling
+     tty when the callee is not root (which is, after all, the threat vector).
+
+ * end */