Debian Bug report logs -
#298058
procmail: Please make suid root installation configurable
Reported by: Martin Pitt <mpitt@debian.org>
Date: Fri, 4 Mar 2005 11:33:05 UTC
Severity: wishlist
Tags: patch
Found in version 3.22-10
Done: Santiago Vila <sanvila@unex.es>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>:
Bug#298058; Package procmail.
(full text, mbox, link).
Acknowledgement sent to Martin Pitt <mpitt@debian.org>:
New Bug report received and forwarded. Copy sent to Santiago Vila <sanvila@debian.org>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Package: procmail
Version: 3.22-10
Severity: wishlist
Tags: patch
Hi!
Currently, procmail is installed as setuid root by default, which is
unnecessary when using it with e. g. exim4 or postfix. Installing it
setgid mail (and using the mail group only when necessary) is much
safer and greatly limits the potential impact of security holes.
You can get the patch from
http://patches.ubuntu.com/patches/procmail.minprivs.diff
it is applied in Ubuntu for half a year now without problems (however,
suid root installation defaults to "no" there).
Please consider adopting it for Debian.
Thanks,
Martin
procmail (3.22-9ubuntu1) unstable; urgency=low
* Minimized sgid privilege usage: right at the program start the effective
group (mail) is reset to the real group (normally the user's primary
group); privileged group 'mail' is just used when creating a previously
missing default mailbox in /var/mail/<username>.
* Added debconf question whether to install procmail setuid root (with
default 'yes' to stay compatible). This is not needed with e. g. exim4 and
postfix, disabling it eliminates a potential security hole.
* Added build-dep po-debconf and dependency debconf.
* Added German translation of debconf question.
-- Martin Pitt <mpitt@debian.org> Sat, 24 Jul 2004 00:52:55 +0200
--
Martin Pitt http://www.piware.de
Ubuntu Developer http://www.ubuntulinux.org
Debian GNU/Linux Developer http://www.debian.org
[signature.asc (application/pgp-signature, inline)]
Reply sent to Santiago Vila <sanvila@unex.es>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to Martin Pitt <mpitt@debian.org>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #10 received at 298058-done@bugs.debian.org (full text, mbox, reply):
On Fri, 4 Mar 2005, Martin Pitt wrote:
> Package: procmail
> Version: 3.22-10
> Severity: wishlist
> Tags: patch
>
> Hi!
>
> Currently, procmail is installed as setuid root by default, which is
> unnecessary when using it with e. g. exim4 or postfix. Installing it
> setgid mail (and using the mail group only when necessary) is much
> safer and greatly limits the potential impact of security holes.
This was already reported by you as Bug#264011, and I still consider
it inappropriate for Debian, which has a lot more MTAs than postfix or exim4.
If you missed the last email in Bug#264011, please read it now.
Information forwarded to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>:
Bug#298058; Package procmail.
(full text, mbox, link).
Acknowledgement sent to Martin Pitt <mpitt@debian.org>:
Extra info received and forwarded to list. Copy sent to Santiago Vila <sanvila@debian.org>.
(full text, mbox, link).
Message #15 received at 298058@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Hi!
Santiago Vila [2005-03-04 13:16 +0100]:
> > Currently, procmail is installed as setuid root by default, which is
> > unnecessary when using it with e. g. exim4 or postfix. Installing it
> > setgid mail (and using the mail group only when necessary) is much
> > safer and greatly limits the potential impact of security holes.
>
> This was already reported by you as Bug#264011, and I still consider
> it inappropriate for Debian, which has a lot more MTAs than postfix or exim4.
>
> If you missed the last email in Bug#264011, please read it now.
Sorry, I forgot about the previous bug and I could not find it in the
current bug list.
For the record, I heavily disagree to your reasoning. You will help
people to lose mail (and much more) if you run programs as root
without any reason (especially for programs which code is as messy as
procmail), and making it easy for people to close this hole is by no
way worthless.
However, I respect that you are the maintainer and decide this, so I
will shut up. Ubuntu just has the policy to offer patches to Debian,
not to force Debian to use it. :-)
Thanks and have a nice day!
Martin
--
Martin Pitt http://www.piware.de
Ubuntu Developer http://www.ubuntulinux.org
Debian GNU/Linux Developer http://www.debian.org
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Santiago Vila <sanvila@debian.org>:
Bug#298058; Package procmail.
(full text, mbox, link).
Acknowledgement sent to Santiago Vila <sanvila@unex.es>:
Extra info received and forwarded to list. Copy sent to Santiago Vila <sanvila@debian.org>.
(full text, mbox, link).
Message #20 received at 298058@bugs.debian.org (full text, mbox, reply):
> > If you missed the last email in Bug#264011, please read it now.
>
> Sorry, I forgot about the previous bug and I could not find it in the
> current bug list.
>
> For the record, I heavily disagree to your reasoning. You will help
> people to lose mail (and much more) if you run programs as root
> without any reason (especially for programs which code is as messy as
> procmail), and making it easy for people to close this hole is by no
> way worthless.
I understand that you want to have as few suid programs as possible in
the system, but it's not as if procmail was being careless with the
suid bit, it changes privileges to the user is delivering to as soon
as it can.
I agree that it should be easy to remove the suid bit, but I think
it's already easy enough to remove the suid bit, using dpkg-statoverride.
Is there really not a way to tell people to use dpkg-statoverride
other than using debconf?
Bug unarchived.
Request was from Stefano Zacchiroli <zack@debian.org>
to control@bugs.debian.org.
(Sun, 10 Apr 2011 08:46:03 GMT) (full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Mon, 09 May 2011 07:44:23 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Wed Oct 11 12:05:49 2017;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.