Vincent Danjean
2007-Jun-26 08:25 UTC
Bug#430637: adduser: Incorrect mode when deluser generate archives
Package: adduser Version: 3.103 Severity: important Tags: patch When generating a archive (BACKUP = 1) with deluser, the perl program set the umask to 600 (decimal number, = 01130 in octal) instead of 0600 (octal number). This lead to an archive with the permissions set to ---x-wx--T You must change the "chmod 600" to "chmod 0600" in /usr/sbin/deluser I set the severity to important because this can have security issues (but I''m not sure of that) Best regards, Vincent -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (990, ''unstable''), (500, ''testing''), (500, ''stable''), (1, ''experimental'') Architecture: i386 (i686) Kernel: Linux 2.6.22-rc5-686 (SMP w/1 CPU core) Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages adduser depends on: ii cdebconf [debconf-2.0] 0.116 Debian Configuration Management Sy ii debconf [debconf-2.0] 1.5.13 Debian configuration management sy ii passwd 1:4.0.18.1-9 change and administer password and ii perl-base 5.8.8-7 The Pathologically Eclectic Rubbis adduser recommends no packages. -- debconf information: * adduser/homedir-permission: true
Joerg Hoh
2007-Jun-26 20:22 UTC
[Adduser-devel] Bug#430637: Bug#430637: adduser: Incorrect mode when deluser generate archives
Package: adduser Tags: fixed-in-svn Hi Vincent On Tue, Jun 26, 2007 at 10:25:23AM +0200, Vincent Danjean wrote:> Package: adduser > Version: 3.103 > Severity: important > Tags: patch > > When generating a archive (BACKUP = 1) with deluser, the perl program > set the umask to 600 (decimal number, = 01130 in octal) instead of 0600 > (octal number). This lead to an archive with the permissions set to > ---x-wx--T > > You must change the "chmod 600" to "chmod 0600" in /usr/sbin/deluser > > I set the severity to important because this can have security issues > (but I''m not sure of that)Fixed in subversion. Thank you for reporting this issue. J?rg -- What did you do to the cat? It looks half-dead. -Schroedinger''s wife -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: Digital signature Url : http://lists.alioth.debian.org/pipermail/adduser-devel/attachments/20070626/5f9d2f72/attachment.pgp
Debian Bug Tracking System
2007-Jul-09 23:21 UTC
[Adduser-devel] Bug#430637: marked as done (adduser: Incorrect mode when deluser generate archives)
Your message dated Mon, 09 Jul 2007 23:17:02 +0000 with message-id <E1I82TW-0003Un-Lv at ries.debian.org> and subject line Bug#430637: fixed in adduser 3.104 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------- next part -------------- An embedded message was scrubbed... From: Vincent Danjean <vdanjean at debian.org> Subject: adduser: Incorrect mode when deluser generate archives Date: Tue, 26 Jun 2007 10:25:23 +0200 Size: 3161 Url: http://lists.alioth.debian.org/pipermail/adduser-devel/attachments/20070709/c0b894ce/attachment-0002.eml -------------- next part -------------- An embedded message was scrubbed... From: Stephen Gran <sgran at debian.org> Subject: Bug#430637: fixed in adduser 3.104 Date: Mon, 09 Jul 2007 23:17:02 +0000 Size: 4739 Url: http://lists.alioth.debian.org/pipermail/adduser-devel/attachments/20070709/c0b894ce/attachment-0003.eml