Tmp directory and files should not be world readable
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
| sbackup (Debian) |
Fix Released
|
Unknown
|
||
| sbackup (Ubuntu) |
Wishlist
|
Unassigned |
Bug Description
Binary package hint: sbackup
When running a backup job, sbackup creates a directory (/tmp/sbackup) where is stores 3 files :
$ ls -l /tmp/sbackup
total 16
-rw-r--r-- 1 root admin 11890 2011-05-19 21:27 excludes.list
-rw-r--r-- 1 root admin 0 2011-05-19 21:27 files.snar
-rw-r--r-- 1 root admin 10 2011-05-19 21:27 includes.list
Those files should not be world readable as they may contain file listing that is meant to be private. This is nothing very important but I think this information should still be kept private.
ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: sbackup 0.11.4-0ubuntu2
ProcVersionSign
Uname: Linux 2.6.38-9-generic x86_64
Architecture: amd64
Date: Thu May 19 21:32:29 2011
PackageArchitec
ProcEnviron:
LANGUAGE=en_CA:en
LANG=en_US.UTF-8
LC_MESSAGES=
SHELL=/bin/bash
SourcePackage: sbackup
UpgradeStatus: No upgrade log present (probably fresh install)
Related branches
Simon Déziel (sdeziel) wrote : | #1 |
Simon Déziel (sdeziel) wrote : | #2 |
Simon Déziel (sdeziel) wrote : | #3 |
Here is a quick fix that chmod 0700 the tmp directory.
tags: | added: patch |
Changed in sbackup (Ubuntu): | |
importance: | Undecided → Wishlist |
Launchpad Janitor (janitor) wrote : | #4 |
This bug was fixed in the package sbackup - 0.11.4-0ubuntu4
---------------
sbackup (0.11.4-0ubuntu4) oneiric; urgency=low
* Apply patch from Simon Déziel to make the temp directory
RWX only by owner instead of by all. (LP: #785495)
-- Daniel T Chen <email address hidden> Wed, 20 Jul 2011 13:41:22 -0400
Changed in sbackup (Ubuntu): | |
status: | New → Fix Released |
tags: |
added: patch-forwarded-debian removed: patch |
Changed in sbackup (Debian): | |
status: | Unknown → New |
Changed in sbackup (Debian): | |
status: | New → Fix Released |
$ lsb_release -rd
Description: Ubuntu 11.04
Release: 11.04
$ apt-cache policy sbackup ca.archive. ubuntu. com/ubuntu/ natty/universe amd64 Packages dpkg/status
sbackup:
Installed: 0.11.4-0ubuntu2
Candidate: 0.11.4-0ubuntu2
Version table:
*** 0.11.4-0ubuntu2 0
500 http://
100 /var/lib/