Let Xvfb setuid.

X11 program.
This commit is contained in:
Mark Stemm 2017-07-05 14:12:54 -07:00
parent d96cf4c369
commit c8c0a97f64

View File

@ -638,7 +638,7 @@
evt.type=setuid and evt.dir=> and
not user.name=root and not somebody_becoming_themself
and not proc.name in (userexec_binaries, mail_binaries, docker_binaries,
sshd, dbus-daemon-lau, ping, ping6, critical-stack-)
sshd, dbus-daemon-lau, ping, ping6, critical-stack-, Xvfb)
and not java_running_sdjagent
output: >
Unexpected setuid call by non-sudo, non-root program (user=%user.name parent=%proc.pname