HN user

chuso

8 karma

[ my public key: https://keybase.io/jprey; my proof: https://keybase.io/jprey/sigs/ftHmQLBE_kZXK4wbFbrKhEDacXtudZrDuMOXk7cWisw ]

This is an OpenPGP proof that connects my OpenPGP key to this Hackernews account. For details check out https://keyoxide.org/guides/openpgp-proofs

[Verifying my OpenPGP key: openpgp4fpr:9C7B2909DFDEDDEEF77A1FE8C49ABD4C42AE40C7]

Posts0
Comments3
View on HN
No posts found.
Copy Fail 3 months ago

It's the same with Gentoo, setuid binaries are installed without read permission.

But modifying a setuid binary is just the demo exploit that was published with the vulnerability disclosure. The vulnerability actually allows modifying four bytes in any readable file. That means system configuration files, other binaries intended to be run by root, libraries... It's not limited to modifying setuid binaries.