Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 65081 - world-writable, non-sticky lock directory
world-writable, non-sticky lock directory
Product: Red Hat Linux
Classification: Retired
Component: mgetty (Show other bugs)
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Nalin Dahyabhai
: Security
Depends On:
  Show dependency treegraph
Reported: 2002-05-17 01:15 EDT by Chris Ricker
Modified: 2008-05-01 11:38 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2002-05-17 01:15:09 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Chris Ricker 2002-05-17 01:15:03 EDT
mgetty-sendfax creates the lockfile directory:

[kaboom@hanuman outgoing]$ ls -ld /var/spool/fax/outgoing/locks
drwxrwxrwx    2 root     root         1024 Mar 28 17:27
[kaboom@hanuman outgoing]$ 

At a mimimum, this directory should instead be chmod 1777 to prevent users from
tampering with others' lock files.
Comment 1 Chris Ricker 2002-11-20 10:10:28 EST
Closing this -- in 8 this directory is now sticky

Note You need to log in before you can comment on or make changes to this bug.