Bug 16738

Summary: suid minicom to uucp
Product: [Retired] Red Hat Linux Reporter: Arenas Belon, Carlo Marcelo <carenas>
Component: minicomAssignee: Bill Nottingham <notting>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 7.1CC: rvokal
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2000-08-24 23:32:07 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Arenas Belon, Carlo Marcelo 2000-08-22 19:04:30 UTC
from bugtraq, tested on RC1

> [lcamtuf@nimue lcamtuf]$ minicom -C foo
> minicom: there is no global configuration file /etc/minirc.dfl
> Ask your sysadm to create one (with minicom -s).
>
> [lcamtuf@nimue lcamtuf]$ ls -l foo
> -rw-rw-r--   1 lcamtuf  uucp            0 Aug 18 12:21 foo
>     ^^                  ^^^^
>
> Any file can be created anywhere with uucp privledges - it will follow
> symlinks. Not nice on systems running uucp services.

Comment 1 Bill Nottingham 2000-08-22 19:40:11 UTC
Yes. The 'anywhere' is misleading; it can only create files
in places group-writable by uucp.

Comment 2 Bill Nottingham 2000-08-24 23:32:05 UTC
*** Bug 16853 has been marked as a duplicate of this bug. ***

Comment 3 Bill Nottingham 2000-08-24 23:32:20 UTC
Should be fixed in minicom-1.83.1-4.