oss-sec mailing list archives
Re: CVE request: psi+ stores the cache file as world-readable
From: gremlin () gremlin ru
Date: Wed, 27 Feb 2013 07:41:28 +0400
On 26-Feb-2013 23:04:24 +0100, Agostino Sarubbo wrote:
Psi+, a fork of psi, stores its files in ~/.cache/psi+ as world-readable.
That's normal - users' home directories are normally accessible only by users themselves, and never by othe users: gremlin@hren:~ > ls -ld . drwx-----x 47 gremlin users 20480 2013-02-26 17:48 ./ This is the most loosy home directory mode I use - that's for accessing ~/www by httpd. Even there I use umask 027 and at other (non-http) servers it's 077. Also, please check the umask setting in this case - I guess psi+ respects it when creating files. -- Alexey V. Vissarionov aka Gremlin from Kremlin <gremlin ПРИ gremlin ТЧК ru> GPG key ID: 0xEF3B1FA8, keyserver: hkp://subkeys.pgp.net GPG key fingerprint: 8832 FE9F A791 F796 8AC9 6E4E 909D AC45 EF3B 1FA8
Current thread:
- CVE request: psi+ stores the cache file as world-readable Agostino Sarubbo (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Seth Arnold (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Agostino Sarubbo (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Kurt Seifried (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable gremlin (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Russ Allbery (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable gremlin (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Agostino Sarubbo (Feb 27)
- Re: CVE request: psi+ stores the cache file as world-readable Russ Allbery (Feb 26)
- Re: CVE request: psi+ stores the cache file as world-readable Seth Arnold (Feb 26)