I hope someone from Mandrake is still reading this list. I got the
advisary for the new kernel in my mail, and installed the new kernel.
Since, then, any number of processes which used to write files that were
writable only by themselves (leafnode as user news, mailman as user mail
and so on) are now writing their files in a world readable setting. My
security logs this morning started reporting files in /var/spool/news,
/var/lock/subsys, /var/run, /var/lib/mailman/lists and so on as being
writable. Checking those directories, I find sure enough that everything
is -rw-rw-rw- -- clearly, this is not acceptable! Can someone please
look into this and fix it and issue a new kernel? This needs to not
continue to happen. When I su to the user IDs in question and do a umask
command, I see 0022 like it should be - so I can't see any reason why this
should be happening.
Thanks!
--Dave
--
David Guntner GEnie: Just say NO!
http://www.akaMail.com/pgpkey/davidg or key server
for PGP Public key
Want to buy your Pack or Services from MandrakeSoft?
Go to http://www.mandrakestore.com