[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#84928: improper permissions of xcircuit 2.0b1-2 related files.



Vampire  <songjh.geo@yahoo.com> writes:
V> Package: xcircuit
V> Version: 2.0b1-2
V> Platform: Debian GNU/Linux 2.2
V> 
V> When I installed xcircuit 2.0b1-2, All of the related files including
V> document have the GID of
V> 1000 and UID of 1000.

This bug only affects the stable version of xcircuit; I've fixed it in 
the unstable version.  (And it actually is a bug, which I can confirm
by downloading the package and running 'tar xzvf' on the data part.)
Is this severe enough to warrant an upload to stable?  The obvious
risk is that a malicious user who happens to have a uid of 1000 could
overwrite the binary and break things for everybody else.

-- 
David Maze             dmaze@mit.edu          http://www.mit.edu/~dmaze/
"Theoretical politics is interesting.  Politicking should be illegal."
	-- Abra Mitchell



Reply to: