Comment 4 for bug 954620

Revision history for this message
Rodney Beede (business2008+launchpad) wrote :

Debian has a Debian specific patch (user-group-modes.patch) that changes the behavior compared to the upstream version of OpenSSH.

If a user ssh file or directory has a group write bit set and that group has no other members besides the user then sshd now allows the use of the ssh file or directory.

I've confirmed this behavior in Ubuntu 12.04.

Upstream the change was not accepted for security reasons and that other distros may not have per-user groups like Debian.

See also:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=314347

https://bugzilla.mindrot.org/show_bug.cgi?id=1060