vim drops ACLs

Bug #23335 reported by Debian Bug Importer
6
Affects Status Importance Assigned to Milestone
vim (Debian)
Fix Released
Unknown
vim (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

Automatically imported from Debian bug report #332425 http://bugs.debian.org/332425

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Thu, 6 Oct 2005 14:44:04 +0200
From: Pierre THIERRY <email address hidden>
To: Debian Bug Tracking System <email address hidden>
Subject: vim drops ACLs

--de1H0RjRxOSdb4we
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Package: vim
Version: 1:6.3-086+1
Severity: grave
Tags: security
Justification: user security hole

This is a bug I can't reproduce everytime. For now, I have a situation
where I can reproduce it, but it happened quite some times before, where
I couldn't reproduce the problem.

When I edit a file with ACLs and save it (:w), the ACLs are lost. The
bug doesn't show up whit vim -u NONE -U NONE.

-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.8-2-k7
Locale: LANG=3Dfr_FR@euro, LC_CTYPE=3Dfr_FR@euro (charmap=3DISO-8859-15)

Versions of packages vim depends on:
ii dpkg 1.13.11 package maintenance system for=
 Deb
ii libc6 2.3.5-6 GNU C Library: Shared librarie=
s an
ii libgpmg1 1.19.6-21 General Purpose Mouse - shared=
 lib
ii libncurses5 5.4-9 Shared libraries for terminal =
hand
ii vim-common 1:6.3-086+1 Vi IMproved - Common files

vim recommends no packages.

-- no debconf information

--=20
<email address hidden>
OpenPGP 0xD9D50D8A

--de1H0RjRxOSdb4we
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDRRwUxe13INnVDYoRAtyZAJwN7X9ROgu3eBJYUPyku8AYpZp+BQCgqSpG
ooAkJ3++X1/v9Lv9VciF6H4=
=zKuT
-----END PGP SIGNATURE-----

--de1H0RjRxOSdb4we--

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Thu, 6 Oct 2005 15:04:02 +0200
From: Norbert Tretkowski <email address hidden>
To: <email address hidden>
Subject: tags

forwarded 332425 <email address hidden>
tags 332425 +confirmed
tags 332425 +upstream

Norbert

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Thu, 6 Oct 2005 11:51:04 -0700
From: Steve Langasek <email address hidden>
To: <email address hidden>
Subject: severity of 332425 is important, tagging 332425

# Automatically generated email from bts, devscripts version 2.9.4
severity 332425 important
 # I don't see a security hole here
tags 332425 - security

Revision history for this message
Martin Pitt (pitti) wrote :

Not a security hole, however, an important bug. Let's see what upstream says to
this (Norbert forwarded it)

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Fri, 7 Oct 2005 15:54:04 -0400
From: Thomas Dickey <email address hidden>
To: Pierre THIERRY <email address hidden>, <email address hidden>
Subject: Re: Bug#332425: vim drops ACLs

--tKW2IUtsqtDRztdT
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Oct 06, 2005 at 02:50:09PM +0200, Pierre THIERRY wrote:
> Package: vim
> Version: 1:6.3-086+1
> Severity: grave
> Tags: security
> Justification: user security hole
>=20
> This is a bug I can't reproduce everytime. For now, I have a situation
> where I can reproduce it, but it happened quite some times before, where
> I couldn't reproduce the problem.
>=20
> When I edit a file with ACLs and save it (:w), the ACLs are lost. The
> bug doesn't show up whit vim -u NONE -U NONE.

iirc, vim has settings that control whether it writes to the original
file, or makes a copy. In the latter case, one would expect to find the
missing ACLs.

--=20
Thomas E. Dickey
http://invisible-island.net
ftp://invisible-island.net

--tKW2IUtsqtDRztdT
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (SunOS)
Comment: For info see http://www.gnupg.org

iD8DBQFDRtJbtIqByHxlDocRArVzAJ0UKQtSUTKQ/wxSxXeJQ+t+vXcxhQCfSQbm
+eyDlUbGsYeitS7SnVu9Gmg=
=mhTC
-----END PGP SIGNATURE-----

--tKW2IUtsqtDRztdT--

Revision history for this message
Martin Pitt (pitti) wrote :

Forwarded upstream, unassigning.

Changed in vim:
assignee: pitti → nobody
Micah Cowan (micahcowan)
Changed in vim:
status: Unconfirmed → Confirmed
Changed in vim:
status: Confirmed → Fix Released
Revision history for this message
Wouter Stomp (wouterstomp-deactivatedaccount) wrote :

Fixed in debian, needs to be merged.

Revision history for this message
Colin Watson (cjwatson) wrote :

As Wouter notes, this is fixed in vim 1:7.1-245+1, which is now in Intrepid.

Changed in vim:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.