Descriptionsysvinit: no-root option in expert installer exposes locally exploitable security flaw
Debian Bugs517018

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sysvinit (PTS)wheezy2.88dsf-41+deb7u1vulnerable
buster, sid2.88dsf-59.10vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


hardly a security issue, if an attacker has local access to the machine and you
don't use encryption or something similar you have lost anyway
- this ^ philosophy is flawed; it should not be trivial to get root just because you
have local access to the machine. it is worth it to make it as difficult as
possible without impacting authorized users. otherwise, why spend so much effort
to make sure xscreensaver, gdm, and login are rock solid?
- i would like to track as low, rather than unimportant

