BugTraq
tar preserves setuid bit Aug 04 2005 11:52PM
Imran Ghory (imranghory gmail com) (3 replies)
Re: GNU tar and the setuid bit Aug 06 2005 03:22PM
David Watson (baikie ehwhat freeserve co uk)
Re: tar preserves setuid bit Aug 05 2005 11:34PM
Sean Comeau (scomeau cansecwest com)
Re: tar preserves setuid bit Aug 05 2005 09:34PM
Neil McKellar (mckellar telusplanet net)
Imran Ghory <imranghory (at) gmail (dot) com [email concealed]> wrote:
> If running as the root user tar restores the original permissions to
> extracted files, this includes the setuid bit. No warning is given to
> the user that this has happened.

From the default man page for tar:

The owner, modification time, and mode are restored (if possible);

This isn't specific to GNU, it's *expected behaviour* for every version of tar.
In fact, a failure to conform to this behaviour breaks essential functionality
of tar. If the root user doesn't know what this tool does or what it's for,
then don't run it.

What part of 'Tape ARchive' wasn't clear? Would you be happy if your backup and
restore procedures failed to actually restore files in their original condition?
Sheesh.
--
Neil (mckellar (at) telusplanet (dot) net [email concealed])

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus