Is there any security risks with files in /proc/<PID>/attr/ globally readable and writeable?
Issue
Root owned files under /proc/1/attr seem to be world readable :
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/task/1/attr/current
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/task/1/attr/exec
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/task/1/attr/fscreate
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/attr/current
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/attr/exec
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/1/attr/fscreate
-rw-rw-rw- 1 root root 0 Mar 19 09:17 /proc/2/task/2/attr/current
Wouldn't this be a security risk?
Environment
Red Hat Enterprise Linux 4 & 5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
