| Summary: | sys-apps/slocate fails to check the +x bit | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Harlan Lieberman-Berg (RETIRED) <hlieberman> |
| Component: | Vulnerabilities | Assignee: | Gentoo's Team for Core System packages <base-system> |
| Status: | RESOLVED INVALID | ||
| Severity: | major | ||
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
|
Description
Harlan Lieberman-Berg (RETIRED)
2007-01-10 23:02:53 UTC
This needs attention. Your file /tmp/dir/a-secret-file is NOT inaccessible to user2. as your user2, 'stat /tmp/dir/a-secret-file'. Merely obscuring the existance of said file is no security, as there are other ways to see that it exists. slocate is accurately reporting that it exists, and is accessible to user2. if you change the perms on /tmp/dir/ to 0700, then slocate ceases to report which is correct. This is correct. My apologies. |