Corel Linux with security flaws
Summary
In January 2000 Corel Linux had security problems because the simple installation gave normal users too many rights. Through the configuration options, all users effectively received administrator rights. Corel wanted to correct the faulty application “Corel Update” with an update.
Ideas
- Simple installation and secure defaults are often at odds.
- An update program with excessive rights became a weak point.
- Users without admin tasks nevertheless received admin rights.
Insights
- Ease of use must not come at the expense of privilege separation.
- Tools with system rights need particularly careful review.
Facts
- Corel Linux was a Canadian distribution based on Debian.
- The vulnerability concerned the “Corel Update” application.
References
Critique
- The report mentions a workaround from Corel but does not describe it.
Remarks
- Corel sold its Linux division to Xandros in 2001.
Recommendations
- Work with a normal user account in everyday use and only use sudo when needed.
- After installing a distribution, check which users have admin rights.
Links to the original source and the Web Archive open in a new tab.