Filipe Almeida wrote:

Hi,

There is a security problem with the implementation of dir/metas/readdir.
This file is readable even if the directory isn't readable by the current user.


Well, this is silly and will be fixed.

This is against traditional unix behavior and is a security issue in many configurations (apache user dir setups, spool directories of some MTA's, etc).

There are other minor issues, like metas/* appearing owned by the current uid and not the actual file owner, and not returning EACCES while changing rwx when you don't have permissions. Just silently ignoring the action.


thanks much, Nikita will fix these.

Regards,
Filipe Almeida

--
Filipe Almeida <[EMAIL PROTECTED]>
http://mega.ist.utl.pt/~filipe/







--
Hans




Reply via email to