[Pkg-citadel-devel] Bug#684964: citadel-server: world writable config file: /etc/citadel/netconfigs/7

Michael Meskes meskes at debian.org
Thu Dec 6 13:47:16 UTC 2012


On Wed, Aug 15, 2012 at 10:14:02AM +0200, Andreas Beckmann wrote:
> during an experimental test with piuparts I noticed that your package
> creates a world writable config file:
> 
>     -rw-rw-rw- 1 citadel root 11 Aug  8 09:45 /etc/citadel/netconfigs/7
> 
> The /etc/citadel/netconfigs directory is citadel:root 0700, so the world
> writable file is not accessible to local users in a default
> installation (therefore only severity important).

Could you please tell us how you created that file? Just installing 8.14-2? Or
did you install 8.14-2 over an old version that already had the file? I just
purged and re-installed my test installation and cannot see a trace of file.

Michael
-- 
Michael Meskes
Michael at Fam-Meskes dot De, Michael at Meskes dot (De|Com|Net|Org)
Michael at BorussiaFan dot De, Meskes at (Debian|Postgresql) dot Org
Jabber: michael.meskes at gmail dot com
VfL Borussia! Força Barça! Go SF 49ers! Use Debian GNU/Linux, PostgreSQL



More information about the Pkg-citadel-devel mailing list