Package: nfs-common Version: 1:1.1.2-6lenny1 Severity: normal Hi,
I noticed on paganini.debian.org that statd was running as root. Apparently rpc.statd is running as the user who owns /var/lib/nfs/sm. This is, by default, statd. However, removing the package (but not purgning) will also remove that directory, and then re-installing the package will again create the directory, but now owned by root. The postinst will not chown it to statd, even tho it probably should. This is potentially a security issue. Cheers, weasel -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

