Hi Nahuel,

2010/10/7 Nahuel Greco <[email protected]>:
> Package: wireshark
> Severity: normal
>
> By default, the 'wireshark' group is not created. The configuration dialog 
> was not shown when doing 'apt-get install wireshark' in a clean installation, 
> maybe because of apt
> settings. It appears correctly with dpkg-reconfigure wireshark-common, but 
> defaults to not create the group. It really may be a security risk? I don't 
> see as such, as the only one
> can add users to the wireshark group is root.
Creating a group itself would not not be a security risk, but would
not be useful either without installing dumpcap with extra privileges.
Installing dumpcap with extra privileges by default does not sound
good from security perspective on the other hand.

I chose to go the safer way in Debian, but I think derived
distributions targeting desktop users could preseed debconf
configuration to make their users' life easier.

Cheers,
Balint



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to