bk99.de entertain the web since 1997

Corel Linux with security flaws

Summary

In January 2000 Corel Linux had security problems because the simple installation gave normal users too many rights. Through the configuration options, all users effectively received administrator rights. Corel wanted to correct the faulty application “Corel Update” with an update.

Ideas

  • Simple installation and secure defaults are often at odds.
  • An update program with excessive rights became a weak point.
  • Users without admin tasks nevertheless received admin rights.

Insights

  • Ease of use must not come at the expense of privilege separation.
  • Tools with system rights need particularly careful review.

Facts

  • Corel Linux was a Canadian distribution based on Debian.
  • The vulnerability concerned the “Corel Update” application.

References

Critique

  • The report mentions a workaround from Corel but does not describe it.

Remarks

  • Corel sold its Linux division to Xandros in 2001.

Recommendations

  • Work with a normal user account in everyday use and only use sudo when needed.
  • After installing a distribution, check which users have admin rights.

Read the original article

Search the Web Archive