Comment 1 for bug 806723

Revision history for this message
Kees Cook (kees) wrote :

n/rdisc6 immediately drop privileges (and check the results), so I have no problem with them being setuid, however, the daemon does not check return codes of setgid or setuidor initgroups (rdnssd.c drop_privileges()). This is almost CVE worthy, and needs to be fixed before it would go into main. Outside of that, the initial design looks good (split root/non-root server, etc).