Bug#856169: Chromium installs a setuid binary without obvious need nor warning

2017-02-25 Thread Michael Gilbert
control: severity -1 wishlist control: retitle -1 chromium: switch to namespace sandbox The sandbox is a necessary security feature. A bug years ago doesn't necessarily mean that it is faulty today. There are lots of new security bugs in chrome every few weeks, and rarely do they have to do

Bug#856169: Chromium installs a setuid binary without obvious need nor warning

2017-02-25 Thread Alain Knaff
Package: chromium Version: 56.0.2924.76-1~deb8u1 Chromium's .deb install a suid root binary (/usr/lib/chromium/chrome-sandbox), potentially exposing the user's system to hostile javascripts downloaded from the untrusted web. This has already been exploited in the past: