[network-admin] network-admin can be run without root-rights

Bug #63766 reported by Christoph Langner
0
Affects Status Importance Assigned to Milestone
gnome-system-tools (Ubuntu)
Invalid
Undecided
Ubuntu Desktop Bugs

Bug Description

I don't know if it is a bug or feature. But if it is a feature, I think it's a secruity hole. Right now it is possible in Ubuntu Edgy Eft to open network-admin with user rights and change the network settings. Just open network-admin out of the settings-menu or type

# network-admin

inside a shell. After you changed some settings you'll find the changes inside /etc/network/interfaces. I don't think this is a good thing. My network-admin version is

# network-admin --version
Gnome network-admin 2.15.5

The rights on my interfaces file are set to the defaults

# ls -al /etc/network/interfaces
-rw-r--r-- 1 root root 282 2006-10-03 15:58 /etc/network/interfaces

The problem could be reproduced on two different systems.

Revision history for this message
Sebastien Bacher (seb128) wrote :

Thanks for your bug. Your user is member of the admin group, no? Non-admin users are not authorized to run it

Changed in gnome-system-tools:
assignee: nobody → desktop-bugs
status: Unconfirmed → Needs Info
Revision history for this message
Christoph Langner (chrissss) wrote :

Yes, only users who are inside the "admin" group may change the network settings this way. I guess this is a nice feature for people who migrate from windows, but it scares the heck of of me... ;)

BTW: The same thing affects users-admin an all other tools out of gnome-system-tools

Isn't it risky to be able to execute all those system tools without getting the necessary rights first?

Revision history for this message
Maftoul Samuel (samuel-maftoul) wrote :

No, it's not that risky because members of group admin can also run sudo. In fact, the security is better than having a root account with a set password, because having a root password means you need to give it to some people. In the current case, every admin has his password.

Changed in gnome-system-tools:
status: Needs Info → Rejected
Revision history for this message
Sebastien Bacher (seb128) wrote :

that will change when policekit start being used (which is not for edgy), discussion about that on bug #59946, I'm marking it duplicate of that one

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.