trinity-users@lists.pearsoncomputing.net

Message: previous - next
Month: January 2017

serious mount problem

From: Istvan Gabor <suseuser04@...>
Date: Wed, 11 Jan 2017 23:00:53 +0100
Hello:

I have Trinity R14.0.4 on openSUSE Leap 42.2.
The desktop has a "My Computer" icon which is a shortcut to media:/.
It opens a window that shows a lot of (all?) hard disk 
volumes/partitions.

The problem:

Normal user can mount any of these partititions. This is a SERIOUS 
security
flaw. Normal user should not be able to mount internal disk partitions
unless the partition is explicitely set so in /etc/fstab using "user" 
or
"users" options. This behavior can lead to unintentional disruption
of raid arrays and enable normal users to modify other users' files in 
other
OSs on other partitions.

It is also very strange that a user running mount command can not mount
those partitions while the desktop system makes it possible.

How can this behavior be changed so that normal could not mount other
partitions?

I would like to report this as a bug, how can I?

Thanks,

Istvan