From owner-freebsd-ports Mon Aug 4 10:35:23 1997 Return-Path: Received: (from root@localhost) by hub.freebsd.org (8.8.5/8.8.5) id KAA14519 for ports-outgoing; Mon, 4 Aug 1997 10:35:23 -0700 (PDT) Received: from limbo.rtfm.net (nathan@rtfm.net [204.141.125.38]) by hub.freebsd.org (8.8.5/8.8.5) with ESMTP id KAA14508 for ; Mon, 4 Aug 1997 10:35:09 -0700 (PDT) Received: (from nathan@localhost) by limbo.rtfm.net (8.8.6/8.8.6) id NAA12428; Mon, 4 Aug 1997 13:36:49 -0400 (EDT) From: Nathan Dorfman Message-Id: <199708041736.NAA12428@limbo.rtfm.net> Subject: Serious Problem in icmpinfo-1.11 Port To: ports@FreeBSD.org Date: Mon, 4 Aug 1997 13:36:48 -0400 (EDT) Cc: obrien@NUXI.com X-Mailer: ELM [version 2.4ME+ PL32 (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-freebsd-ports@FreeBSD.org X-Loop: FreeBSD.org Precedence: bulk Here is the last couple of lines of a make install for icmpinfo-1.11 ports as included in 3.0-970718-SNAP: ===> Installing for icmpinfo-1.11 install -c -s -o bin -g bin -m 555 /usr/ports/net/icmpinfo/work/icmpinfo-1.11/icmpinfo /usr/local/bin /usr/sbin/chown root /usr/local/bin /* umm, ok */ /bin/chmod 4555 /usr/local/bin /* umm, not ok! */ install -c -o bin -g bin -m 444 /usr/ports/net/icmpinfo/work/icmpinfo-1.11/icmpinfo.man /usr/local/man/man1/icmpinfo.1 install -c -o bin -g bin -m 444 /usr/ports/net/icmpinfo/work/icmpinfo-1.11/README /usr/local/share/doc/icmpinfo ===> Compressing manual pages for icmpinfo-1.11 ===> Registering installation for icmpinfo-1.11 If you look at the 2nd and 4th lines, it makes /usr/local/bin setuid root! Probably in an attempt to make icmpinfo setuid root: # ls -ld /usr/local/bin dr-sr-xr-x 2 root wheel 5632 Aug 4 13:25 /usr/local/bin Anyone else see something like this?