-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Package: adduser Version: 3.59 Severity: critical Some users have default /bin as home directory. deluser will remove /bin if such a user is removed and REMOVE_HOME is set to 1 in the config. After that the system has to be mostely new installed. This might be a critical bug in adduser or in the debian policy to create such cracy users. The bug might happens if you think of cleaning the system of from unnecesarry users to hardening it. Please at least check for such directorys like /bin, /sbin, /usr/bin, /usr/sbin, /usr or / to not completely remove!!! - -- System Information: Debian Release: 3.1 APT prefers unstable APT policy: (800, ''unstable''), (700, ''testing'') Architecture: i386 (i686) Kernel: Linux 2.4.29 Locale: LANG=de_DE, LC_CTYPE=de_DE (charmap=ISO-8859-1) (ignored: LC_ALL set to de_DE) Versions of packages adduser depends on: ii debconf 1.4.42 Debian configuration management sy ii passwd 1:4.0.3-30.9 change and administer password and ii perl-base 5.8.4-6 The Pathologically Eclectic Rubbis - -- debconf information: * adduser/homedir-permission: true - -- Klaus Ethgen http://www.ethgen.de/ pub 2048R/D1A4EDE5 2000-02-26 Klaus Ethgen <Klaus@Ethgen.de> Fingerprint: D7 67 71 C4 99 A6 D4 FE EA 40 30 57 3C 88 26 2B -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iQEVAwUBQgNfdJ+OKpjRpO3lAQKBMAf+K7Q17rRMa+qXjBK4x1RsM29bEEeIe31n VT4rp4Z0R+ratPCPpP4jHVBqaw2lTRlwQX+xCwq5sb68X0nQ6IZNC7ZYZ4s8m2O9 LpHzPUEP/SbWOZjnV8PLpkUaS9rn8Cjg9Yn0ZIt7aht/GMdkLZZH0w1kytNQ2MZa qGRoCDQYTp41WCaAjoLpTxlJmqSc3UewtZGiHvw2r4iJYId7Ip1/bkUhVw3NUBx1 QNQgMa51CEHDjKkz9c6oCR+aR5znra/MrGmq1ErDhuIuRJfsNoRAKUv/7jV9iMZR FQ6KfkJ7RWUrBkjPhThtNhU6dXqVCpZNfj0XzSvBj3cfx4ghu4Rt5w==+s+f -----END PGP SIGNATURE-----
Debian Bug Tracking System
2005-May-06 12:33 UTC
[Adduser-devel] Bug#293559: marked as done (deluser removes /bin)
Your message dated Fri, 6 May 2005 14:21:10 +0200 with message-id <20050506122110.GA17295@lefler.int.l21.ma.zugschlus.de> and subject line Closing bugs has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 4 Feb 2005 11:41:50 +0000>From Klaus@ethgen.de Fri Feb 04 03:41:50 2005Return-path: <Klaus@ethgen.de> Received: from static-195-068.catv.glattnet.ch (hathi.ethgen.de) [80.242.195.68] by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1Cx1qP-0002i1-00; Fri, 04 Feb 2005 03:41:50 -0800 Received: from ikki.ket ([192.168.17.4]) by hathi.ethgen.de with asmtp (TLS-1.0:RSA_AES_128_CBC_SHA:16) (Exim 4.34) id 1Cx1qJ-0002Jm-75; Fri, 04 Feb 2005 12:41:43 +0100 Received: from klaus by ikki.ket with local (Exim 4.44) id 1Cx1qG-0000af-Ry; Fri, 04 Feb 2005 12:41:40 +0100 Date: Fri, 4 Feb 2005 12:41:40 +0100 From: Klaus Ethgen <Klaus@Ethgen.de> To: Debian Bug Tracking System <submit@bugs.debian.org> Subject: deluser removes /bin Message-ID: <20050204114140.GA1846@ikki> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii; x-action=pgp-signed Content-Disposition: inline X-Reportbug-Version: 3.7.1 User-Agent: Mutt/1.5.6+20040523i Delivered-To: submit@bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-7.2 required=4.0 tests=BAYES_00,HAS_PACKAGE, REMOVE_REMOVAL_NEAR autolearn=no version=2.60-bugs.debian.org_2005_01_02 X-Spam-Level: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Package: adduser Version: 3.59 Severity: critical Some users have default /bin as home directory. deluser will remove /bin if such a user is removed and REMOVE_HOME is set to 1 in the config. After that the system has to be mostely new installed. This might be a critical bug in adduser or in the debian policy to create such cracy users. The bug might happens if you think of cleaning the system of from unnecesarry users to hardening it. Please at least check for such directorys like /bin, /sbin, /usr/bin, /usr/sbin, /usr or / to not completely remove!!! - -- System Information: Debian Release: 3.1 APT prefers unstable APT policy: (800, ''unstable''), (700, ''testing'') Architecture: i386 (i686) Kernel: Linux 2.4.29 Locale: LANG=de_DE, LC_CTYPE=de_DE (charmap=ISO-8859-1) (ignored: LC_ALL set to de_DE) Versions of packages adduser depends on: ii debconf 1.4.42 Debian configuration management sy ii passwd 1:4.0.3-30.9 change and administer password and ii perl-base 5.8.4-6 The Pathologically Eclectic Rubbis - -- debconf information: * adduser/homedir-permission: true - -- Klaus Ethgen http://www.ethgen.de/ pub 2048R/D1A4EDE5 2000-02-26 Klaus Ethgen <Klaus@Ethgen.de> Fingerprint: D7 67 71 C4 99 A6 D4 FE EA 40 30 57 3C 88 26 2B -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iQEVAwUBQgNfdJ+OKpjRpO3lAQKBMAf+K7Q17rRMa+qXjBK4x1RsM29bEEeIe31n VT4rp4Z0R+ratPCPpP4jHVBqaw2lTRlwQX+xCwq5sb68X0nQ6IZNC7ZYZ4s8m2O9 LpHzPUEP/SbWOZjnV8PLpkUaS9rn8Cjg9Yn0ZIt7aht/GMdkLZZH0w1kytNQ2MZa qGRoCDQYTp41WCaAjoLpTxlJmqSc3UewtZGiHvw2r4iJYId7Ip1/bkUhVw3NUBx1 QNQgMa51CEHDjKkz9c6oCR+aR5znra/MrGmq1ErDhuIuRJfsNoRAKUv/7jV9iMZR FQ6KfkJ7RWUrBkjPhThtNhU6dXqVCpZNfj0XzSvBj3cfx4ghu4Rt5w==+s+f -----END PGP SIGNATURE----- --------------------------------------- Received: (at 271829-done) by bugs.debian.org; 6 May 2005 12:22:10 +0000>From mh+debian-packages@zugschlus.de Fri May 06 05:22:10 2005Return-path: <mh+debian-packages@zugschlus.de> Received: from 5301d.unt0.torres.l21.ma.zugschlus.de (torres.int.l21.ma.zugschlus.de) [217.151.83.1] (Debian-exim) by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1DU1qM-0003FP-00; Fri, 06 May 2005 05:22:10 -0700 Received: from lefler.int.l21.ma.zugschlus.de ([192.168.130.38]) by torres.int.l21.ma.zugschlus.de with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA:32) (Exim 4.50) id 1DU1pQ-0002Pk-2p; Fri, 06 May 2005 14:21:12 +0200 Received: from mh by lefler.int.l21.ma.zugschlus.de with local (Exim 4.50) id 1DU1pP-0004fU-0I; Fri, 06 May 2005 14:21:11 +0200 Date: Fri, 6 May 2005 14:21:10 +0200 From: Marc Haber <mh+debian-packages@zugschlus.de> To: 293559-done@bugs.debian.org, 283110-done@bugs.debian.org, 287535-done@bugs.debian.org, 268841-done@bugs.debian.org, 268837-done@bugs.debian.org, 286227-done@bugs.debian.org, 268402-done@bugs.debian.org, 278937-done@bugs.debian.org, 270266-done@bugs.debian.org, 279659-done@bugs.debian.org, 273010-done@bugs.debian.org, 271142-done@bugs.debian.org, 271829-done@bugs.debian.org, 231809-done@bugs.debian.org Cc: Marc Haber <mh+debian-packages@zugschlus.de> Subject: Closing bugs Message-ID: <20050506122110.GA17295@lefler.int.l21.ma.zugschlus.de> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.9i Delivered-To: 271829-done@bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-3.0 required=4.0 tests=BAYES_00 autolearn=no version=2.60-bugs.debian.org_2005_01_02 X-Spam-Level: X-CrossAssassin-Score: 7 These bugs have been tagged as fixed-in-experimental, and are now being closed completely. That should have happened long ago. Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don''t trust Computers. They | Mailadresse im Header Mannheim, Germany | lose things." Winona Ryder | Fon: *49 621 72739834 Nordisch by Nature | How to make an American Quilt | Fax: *49 621 72739835