Description of problem: In /usr/share/doc/mmv-1.01b the files changelog and copyright are group and world writetable, which they im my opinion should not be. Version-Release number of selected component (if applicable): 1.01b-5.fc5 and mmv-1.01b-3.fc4 How reproducible: Always Steps to Reproduce: 1. ls -la /usr/share/doc/mmv-* Actual results: [...] -rw-rw-rw- 1 root root 3599 30. Sep 2005 changelog -rw-rw-rw- 1 root root 1271 30. Sep 2005 copyright [...] Expected results: -rw-r--r-- 1 root root 3599 30. Sep 2005 changelog -rw-r--r-- 1 root root 1271 30. Sep 2005 copyright
yup, I only just noticed this a few weeks ago... there's a fix in cvs devel branch right now, but I'll work on pushing out an update soon. thanks for the report.
Just in case you missed it, the problem remains unfixed in the FE3 package.
hmmm, I thought extras support lifetime was the last two releases? Am I wrong? GA on fc5 was 3/20 so I just didn't bother with a fc3 release. Actually, looking back at the devel changelog, I committed an initial, but incomplete buggy fix right on 3/20... so does that mean I'm on the hook for an fc3 release? :) That being said, I can make a release if you feel its still warranted or I'm mistaken on the support lifetime.
ok, I just talked with tibbs on irc and that made me aware of the security team. I'm handing the fc3 security bug off to you guys (the fedora security team). if this isn't the proper procedure or wrong in any way let me know. thx.