-
Notifications
You must be signed in to change notification settings - Fork 19
WordPerfect security flaws documentation #48
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hah, yes, I think that report is correct - although there's an easy workaround, you can do I don't have an AppArmor profile, however the only untrusted data it parses is if you open an untrusted document - writing and managing your own documents should be fine. I think networking isn't necessary, but printing does use UNIX domain sockets for IPC. |
Incidentally, that advisory is a fun find, interesting history! |
Thanks. It'd be great if you fix that issue. As you probably have already noticed, TMPDIR works, but wp will still use /tmp/wpc-`hostname` if the directory doesn't exist.
I tried running wp in firejail since that's the easiest and it immediately failed. Apparently, I can't have both 64-bit and 32-bit firejail installed at the same time. Instead, I created a user account ("wpjail") just for running wp and am satisfied that it is secure enough for my needs. I use it with By the way, if you do create a security/flaws document, you may want to mention a few other things I noticed:
(Whoops, that list went way longer than I thought it would. Sorry.) |
There were some notes about how printing works in the wiki, it's here https://github.com/taviso/wpunix/wiki/Hacking#printing I'll think about moving things to per-user tmp directories, I'm not sure if there are any features that will break yet (not that I think anyone is using multi-user features 😂). Maybe the The The |
I understand that it is not a priority for this project, but it would be helpful if there was a list of the security flaws to be aware of in WordPerfect. As I recall, it was designed for a single-user computer and did not have any thought to security. For example, https://insecure.org/sploits/wordperfect7.fileperms.html mentions files being created in /tmp with permissions 666.
Also, if there is any advice on hardening an install of WordPerfect, I'd appreciate it. For example, has anybody had experience using running it confined by AppArmor / firejail? Are there pre-made profiles? I presume networking can be disabled, but what capabilities does WordPerfect actually require to run?
The text was updated successfully, but these errors were encountered: