Bug 67311 - world-writable non-sticky lock directory
Summary: world-writable non-sticky lock directory
Status: CLOSED RAWHIDE
Alias: None
Product: Red Hat Linux Beta
Classification: Retired
Component: mgetty   
(Show other bugs)
Version: beta3
Hardware: i386 Linux
medium
medium
Target Milestone: ---
Assignee: Nalin Dahyabhai
QA Contact:
URL:
Whiteboard:
Keywords: Security
: 70770 (view as bug list)
Depends On:
Blocks: 67218
TreeView+ depends on / blocked
 
Reported: 2002-06-22 04:19 UTC by Chris Ricker
Modified: 2008-05-01 15:38 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2002-08-23 19:51:13 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Chris Ricker 2002-06-22 04:19:20 UTC
This bug also exists in Red Hat 7.3 (bug #65081) and needs to be fixed there as
well.

The mgetty-sendfax lockfile directory is world-writable and not sticky.

[root@localhost outgoing]# ls -ld /var/spool/fax/outgoing/locks/
drwxrwxrwx    2 root     root         4096 May 26 23:05
/var/spool/fax/outgoing/locks/
[root@localhost outgoing]# 


At a minimum, this should be chmod 1777

Comment 1 Chris Ricker 2002-07-10 02:59:17 UTC
still true with beta3

Comment 2 Elliot Lee 2002-08-23 19:51:07 UTC
*** Bug 70770 has been marked as a duplicate of this bug. ***

Comment 3 Elliot Lee 2002-08-23 20:26:58 UTC
mgetty-1.1.28-8 should fix this


Note You need to log in before you can comment on or make changes to this bug.