Red Hat Bugzilla – Bug 188388
files in /usr/share/doc/mmv-1.01b are group and world writetable
Last modified: 2007-11-30 17:11:30 EST
Description of problem:
In /usr/share/doc/mmv-1.01b the files changelog and copyright are group and
world writetable, which they im my opinion should not be.
Version-Release number of selected component (if applicable):
1.01b-5.fc5 and mmv-1.01b-3.fc4
Steps to Reproduce:
1. ls -la /usr/share/doc/mmv-*
-rw-rw-rw- 1 root root 3599 30. Sep 2005 changelog
-rw-rw-rw- 1 root root 1271 30. Sep 2005 copyright
-rw-r--r-- 1 root root 3599 30. Sep 2005 changelog
-rw-r--r-- 1 root root 1271 30. Sep 2005 copyright
yup, I only just noticed this a few weeks ago... there's a fix in cvs devel
branch right now, but I'll work on pushing out an update soon.
thanks for the report.
Just in case you missed it, the problem remains unfixed in the FE3 package.
hmmm, I thought extras support lifetime was the last two releases? Am I wrong?
GA on fc5 was 3/20 so I just didn't bother with a fc3 release. Actually,
looking back at the devel changelog, I committed an initial, but incomplete
buggy fix right on 3/20... so does that mean I'm on the hook for an fc3 release? :)
That being said, I can make a release if you feel its still warranted or I'm
mistaken on the support lifetime.
ok, I just talked with tibbs on irc and that made me aware of the security team.
I'm handing the fc3 security bug off to you guys (the fedora security team).
if this isn't the proper procedure or wrong in any way let me know. thx.