Package: tiger
Version: 1:3.2.4~rc1-3.5
Severity: important

Dear Maintainer,

after the cron command run by root

test -x /usr/sbin/tigercron && { [ -r "$DEFAULT" ] && . "$DEFAULT" ; nice 
-n$NICETIGER /usr/sbin/tigercron -q ; }

the email body is 

[...]
lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
      Output information may be incomplete.
lsof: WARNING: can't stat() fuse.kio-fuse file system 
/run/user/1000/kio-fuse-zbmsAg
      Output information may be incomplete.
[...]

nothing else.

Searching on google I found this 
https://www.openwall.com/lists/oss-security/2024/05/11/3

[...]
These are FUSE filesystems running as uid 1000, which by default are
not accessible *by root* - which might seem strange at first glance,
but is an intentional security mechanism to protect root from being
attacked by uid 1000 (see mount.fuse3(8) for details).
[...]

so

[...]
ven lug 24 10:58:00 stefano@G5045 
~ <bash> $ lsof /run/user/1000/doc

ven lug 24 10:58:07 stefano@G5045 
~ <bash> $ lsof /run/user/1000/kio-fuse-zbmsAg

ven lug 24 10:58:27 stefano@G5045 
~ <bash> $ su -
Password: 

ven lug 24 10:58:37 @G5045: 
~ <-bash> # lsof /run/user/1000/doc
lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
      Output information may be incomplete.
lsof: WARNING: can't stat() fuse.kio-fuse file system 
/run/user/1000/kio-fuse-zbmsAg
      Output information may be incomplete.
lsof: status error on /run/user/1000/doc: Permission denied

ven lug 24 10:58:44 @G5045:
[...]


Thanks 

Stefano

-- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (903, 'unstable'), (500, 'oldoldstable-updates'), (500, 
'oldoldstable-security'), (500, 'oldoldstable'), (500, 'testing'), (400, 
'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 7.1.4+deb14-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=it_IT.UTF-8, LC_CTYPE=it_IT.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:it
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages tiger depends on:
ii  binutils               2.46.90.20260712-1
ii  bsdutils               1:2.42.2-2
ii  debconf [debconf-2.0]  1.5.92
ii  debianutils            5.23.2
ii  libc6                  2.42-17
ii  lsb-release            12.1-2
ii  net-tools              2.10-2
ii  ucf                    3.0056

Versions of packages tiger recommends:
ii  chkrootkit                      0.59-1
ii  john                            1.9.0-3
ii  postfix [mail-transport-agent]  3.11.5-1
ii  tripwire                        2.4.3.7-7

Versions of packages tiger suggests:
ii  lsof   4.99.4+dfsg-2
pn  lynis  <none>

-- debconf information:
* tiger/mail_rcpt: root
* tiger/policy_adapt:

Reply via email to