[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: world writable /usr/lib/libguile.so.6.0.0



On 22/11/99 Peter Makholm wrote:

Just downloaded libguile6 and unared and untared it. Permissions in
that version seems fine. And there is notihing in postinst that
changes this.

I found version 1.3-16.1 which versions are you using?

1.3-16.1

how could that happen ? I have not yet studied how .debs work internally so is it the permissions stored in the embedded .tar file that are used? or is there a permission definition elsewhere (al la RPM .spec) ??

maybe we should add a script to cron that runs a scan for faulty permissions as well like suidregister scans for altered/new suids, mailing the results to root. I don't know how long this has been this way but its obviously not an isolated problem. checking for group writable files that shouldn't be would be a good idea too.



Best Regards,
Ethan Benson
To obtain my PGP key: http://www.alaska.net/~erbenson/pgp/


Reply to: