Bug#19146: marked as done (FIXED in NMU [was: dpkg: dselect leaves 'available' and 'status' with wrong permissions])
Your message dated Mon, 5 Oct 1998 22:55:20 -0600
with message-id <199810060455.WAA04287@rover.gag.com>
and subject line believed fixed
has caused the attached bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I'm
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
(administrator, Debian bugs database)
Received: (at submit) by bugs.debian.org; 8 Mar 1998 13:14:14 +0000
Received: (qmail 872 invoked from network); 8 Mar 1998 13:14:13 -0000
Received: from pop3.tu-dresden.de (220.127.116.11)
by debian.novare.net with SMTP; 8 Mar 1998 13:14:13 -0000
Received: from rmail.urz.tu-dresden.de (actually RKS4f.urz.tu-dresden.de)
by rks3 with SMTP (PP); Sun, 8 Mar 1998 14:07:30 +0100
Received: from physik.phy.tu-dresden.de (actually pbtrs2.phy.tu-dresden.de)
by rmail with SMTP (PP); Sun, 8 Mar 1998 14:04:40 +0100
Received: by physik.phy.tu-dresden.de (AIX 3.2/UCB 5.64/4.03) id AA23375;
Sun, 8 Mar 1998 14:09:46 +0100
From: email@example.com (Ulf Jaenicke-Roessler)
Subject: dpkg: dselect leaves 'available' and 'status' with wrong permissions
To: firstname.lastname@example.org (debian bugs)
Date: Sun, 8 Mar 1998 14:09:46 +0100 (MET)
X-Mailer: ELM [version 2.4ME+ PL30 (25)]
Content-Type: text/plain; charset=US-ASCII
I already reported this for 18.104.22.168, but the bug disappeared from
the bugs list.
If dselect creates (writes to) new files /var/lib/dpkg/available
and /var/lib/dpkg/status, it uses the umask setting of the calling
process. I use umask 007, sometimes 077, for root. So I always have
640 or 600 permissions for both files.
This prevents any "normal" user to read the database, which is a
Bad Thing (TM).
BTW, dpkg works fine in this context. It sets 644 rights.