weak file permission with default config/installation
Bug #1251447 reported by
Hannes Koschier
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
automysqlbackup (Debian) |
Fix Released
|
Unknown
|
|||
automysqlbackup (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
Hi,
after a standard installation of the automysqlbackup package the packages create the default folder for backups under
/var/lib/
with permission 755 - so everyone can read the dumps.
root@kvm11152:~# ls -la /var/lib/
insgesamt 8
drwxr-xr-x 2 root root 4096 Feb 15 2012 .
drwxr-xr-x 43 root root 4096 Nov 14 00:57 ..
information type: | Private Security → Public Security |
Changed in automysqlbackup (Debian): | |
status: | Unknown → New |
Changed in automysqlbackup (Debian): | |
status: | New → Fix Released |
To post a comment you must log in.
Thanks for the report, I can confirm:
$ ls -lad / /var /var/lib /var/lib/ automysqlbackup automysqlbackup
drwxr-xr-x 24 root root 4096 Oct 29 18:23 /
drwxr-xr-x 13 root root 4096 Oct 29 18:24 /var
drwxr-xr-x 59 root root 4096 Nov 14 15:23 /var/lib
drwxr-xr-x 2 root root 4096 Feb 15 2012 /var/lib/
automysqlbackup is in universe, thus it is community- supported. If you /wiki.ubuntu. com/SecurityTea m/UpdateProcedu res
are able, I suggest coordinating with upstream and posting a debdiff for
this issue. When a debdiff is available, members of the security team
will review it and publish the package. See the following link for more
information: https:/
Thanks