Bug 188388

Summary: files in /usr/share/doc/mmv-1.01b are group and world writetable
Product: [Fedora] Fedora Reporter: Till Maas <opensource>
Component: mmvAssignee: Zing <zing>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: 5CC: extras-qa
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-04-10 18:31:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Till Maas 2006-04-08 22:07:38 UTC
Description of problem: 
 
In /usr/share/doc/mmv-1.01b the files changelog and copyright are group and 
world writetable, which they im my opinion should not be. 
 
Version-Release number of selected component (if applicable): 
 
1.01b-5.fc5 and mmv-1.01b-3.fc4 
 
How reproducible: 
 
Always 
 
Steps to Reproduce: 
1. ls -la /usr/share/doc/mmv-* 
   
Actual results: 
 
[...] 
-rw-rw-rw-    1 root root  3599 30. Sep 2005  changelog 
-rw-rw-rw-    1 root root  1271 30. Sep 2005  copyright 
[...] 
 
Expected results: 
 
-rw-r--r--    1 root root  3599 30. Sep 2005  changelog 
-rw-r--r--    1 root root  1271 30. Sep 2005  copyright

Comment 1 Zing 2006-04-09 20:18:11 UTC
yup, I only just noticed this a few weeks ago... there's a fix in cvs devel
branch right now, but I'll work on pushing out an update soon.

thanks for the report.

Comment 2 Ville Skyttä 2006-07-31 21:00:14 UTC
Just in case you missed it, the problem remains unfixed in the FE3 package.

Comment 3 Zing 2006-08-01 00:21:17 UTC
hmmm, I thought extras support lifetime was the last two releases?  Am I wrong?

GA on fc5 was 3/20 so I just didn't bother with a fc3 release.  Actually,
looking back at the devel changelog, I committed an initial, but incomplete
buggy fix right on 3/20... so does that mean I'm on the hook for an fc3 release? :)

That being said, I can make a release if you feel its still warranted or I'm
mistaken on the support lifetime.

Comment 4 Zing 2006-08-01 00:53:37 UTC
ok, I just talked with tibbs on irc and that made me aware of the security team.
 I'm handing the fc3 security bug off to you guys (the fedora security team). 

if this isn't the proper procedure or wrong in any way let me know. thx.