Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 150685 - net-irc/psybnc SSL keys are world readable
Summary: net-irc/psybnc SSL keys are world readable
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Default Configs (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~ [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-09 15:23 UTC by Muelli
Modified: 2006-10-18 08:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Muelli 2006-10-09 15:23:37 UTC
Hi,

after installing psyBNC I recognized that it's SSL Key is world readable:

# ls -l /opt/psybnc/key/*
-rw-r--r-- 1 psybnc psybnc 1671 Oct  9 23:56 /opt/psybnc/key/psybnc.cert.pem
-rw-r--r-- 1 psybnc psybnc 1675 Oct  9 23:56 /opt/psybnc/key/psybnc.key.pem
-rw-r--r-- 1 psybnc psybnc 1062 Oct  9 23:56 /opt/psybnc/key/psybnc.req.pem

At least the key should not be world readable. Please add some chmod magic to the ebuild.

Regards
  Muelli
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-11 06:42:09 UTC
gurligebis, pls verify/fix

"Muelli", can we open this bug to the public?
Comment 2 Muelli 2006-10-11 13:57:55 UTC
Hi,

of course you can, but If I were an admin who has a couple of users, I'd appreciate a new ebuild like net-irc/psybnc-2.3.2.7-r1 which fixes this issue before everyone knows how to read the private key... So my oppinion is, to fix the ebuild -which is rather simple- and then open this bug for the public.

Regards
  Muelli
Comment 3 Bjarke Istrup Pedersen (RETIRED) gentoo-dev 2006-10-18 07:34:29 UTC
Fixing it now :-)
Comment 4 Bjarke Istrup Pedersen (RETIRED) gentoo-dev 2006-10-18 08:19:09 UTC
Fixed :-)
Has been added to CVS
Comment 5 Matthias Geerdsen (RETIRED) gentoo-dev 2006-10-18 08:26:01 UTC
thanks bjarke

opening the bug now

The ebuild is not stable on any arch, so this bug can stay closed and no GLSA will be issued.