vm-builder images and configuration files should not be world readable

Bug #386463 reported by Dustin Kirkland 
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
vm-builder (Ubuntu)
Confirmed
Medium
Unassigned
Lucid
Won't Fix
Medium
Unassigned

Bug Description

From yann2 in #ubuntu-virt:

"Permissions incorrect? libvirt group users should be able to access /etc/libvirt/qemu/* - images generated by ubuntuvmbuilder are readable by the world (not good at all imho)"

It is request by this user that vm-builder configs and images are not created world-readable.

:-Dustin

Revision history for this message
Dustin Kirkland  (kirkland) wrote :

Unmarked security, per irc discussion with the security team.

They'll comment further.

:-Dustin

security vulnerability: yes → no
visibility: private → public
Changed in vm-builder (Ubuntu):
assignee: nobody → Soren Hansen (soren)
status: New → Confirmed
Soren Hansen (soren)
Changed in vm-builder (Ubuntu):
assignee: Soren Hansen (soren) → nobody
assignee: nobody → Canonical Security Team (canonical-security)
Revision history for this message
Kees Cook (kees) wrote :

Images should absolutely not be world-readable (they could contain all kinds of things). Configs should probably follow this as well, though I'm unaware of anything sensitive in the configurations.

Changed in vm-builder (Ubuntu):
assignee: Canonical Security Team (canonical-security) → Soren Hansen (soren)
Steve Beattie (sbeattie)
Changed in vm-builder (Ubuntu):
importance: Undecided → Medium
Soren Hansen (soren)
Changed in vm-builder (Ubuntu):
milestone: none → ubuntu-10.04
Thierry Carrez (ttx)
Changed in vm-builder (Ubuntu Lucid):
milestone: ubuntu-10.04 → none
Soren Hansen (soren)
Changed in vm-builder (Ubuntu):
assignee: Soren Hansen (soren) → nobody
Changed in vm-builder (Ubuntu Lucid):
assignee: Soren Hansen (soren) → nobody
Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in vm-builder (Ubuntu Lucid):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.