Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Tool

Version

Checker

Description

Compass/ROSE

 

 

Can detect some violations of this rule. In particular, it warns when calls to setgid() are immediately preceded by a call to setuid().

Klocwork

Include Page
Klocwork_V
Klocwork_V

SV.FIU.PERMISSIONS
SV.USAGERULES.PERMISSIONS

 

...

Search for vulnerabilities resulting from the violation of this rule on the CERT website.

Related Guidelines

...

Privilege Sandbox Issues [XYO]
MITRE CWE

...

...

Execution with unnecessary privileges

...


...

...

...

Incorrect behavior order

...

...

Bibliography

[Chen 2002]"Setuid Demystified"
[Dowd 2006]Chapter 9, "UNIX I: Privileges and Files"
[Open Group 2004]

...

...

...

[Tsafrir 2008]"The Murky Issue of Changing Process Identity: Revising 'Setuid Demystified'"

 

...