Comment 7 for bug 10192

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Wed, 10 Nov 2004 18:08:36 +0100
From: Andreas Barth <email address hidden>
To: Michal Zimen <email address hidden>, <email address hidden>
Subject: Re: Bug#280632: libc6: Ordinary user can delete files owned by other user, root files too.

* Michal Zimen (<email address hidden>) [041110 17:45]:
> normal user can delete files, which is not owned by him.

This is part of the defined unix behaviour. If you can delete a file
depends on the directory. If the user can write to the directory, he can
delete the file (with the exception if the directory is sticky, he need
also to own the file - but that's an later extension).

> but at: /usr/bin/, ~/, /tmp it is really possible.

I doubt that it works in /tmp on a regular debian system, also that it
works in /usr/bin, and in ~ by someone else than the user whose home
directory it is. If it does on your system, please show ls -ld of the
directory.

Cheers,
Andi
--
   http://home.arcor.de/andreas-barth/
   PGP 1024/89FB5CE5 DC F1 85 6D A6 45 9C 0F 3B BE F1 D0 C5 D1 D9 0C