First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 44397
Alias:
Product:
Component:
Status: CLOSED
Resolution: TEST-REQUEST
Assigned To: Stuart Herbert (RETIRED) <stuart@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: repugnant <bugreporter@jwoltman.net>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 44397 depends on: Show dependency tree
Show dependency graph
Bug 44397 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)





View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-03-11 15:24 0000
After emerging net-mail/popfile-0.21.1 I had trouble running it (including a
missing dependency - see bug 44394).  But there are other problems.  The files
installed to /usr/share/popfile/ are *world* writeable, which probably
represents a security risk.  I think someone could change the modules. I rated
this a "Major" bug because I'm not 100% sure of the security problems.

Reproducible: Didn't try
Steps to Reproduce:
1. emerge popfile
2. check out the permissions in /usr/share/popfile/*

Actual Results:  
Most files were user, group, and other writeable

Expected Results:  
Only root should be able to write I guess.

------- Comment #1 From Stuart Herbert (RETIRED) 2004-03-17 11:08:06 0000 -------
Updated the ebuild in portage; it should be appearing on a local rsync mirror
in about an hour or so.

------- Comment #2 From Stuart Herbert (RETIRED) 2004-03-27 16:05:51 0000 -------
Closing bug - no feedback from submitter

------- Comment #3 From repugnant 2004-03-27 16:16:06 0000 -------
I'm sorry for not responding; I didn't realize that I was supposed to try it
out, since I had fixed the problem manually myself.  I will pay more attention
next time I submit a bug.  Thanks for fixing it :)

First Last Prev Next    No search results available      Search page      Enter new bug