Bug#668536: [Packaging] Bug#668536: munin: The tempfile location has to be predictable, but not creatable by anyone.

2012-04-14 Thread Holger Levsen
Hi, On Freitag, 13. April 2012, Helmut Grohne wrote: kjetilho doesn't help if the attacker can do mkdir /tmp/subdir; chmod 777 /tmp/subdir after a reboot I was about to write this, but it seemed too obvious to me. Use a @reboot cronjob. ;-) we have an init script to do that :) So you

Bug#668536: munin: The tempfile location has to be predictable, but not creatable by anyone.

2012-04-13 Thread Steve Schnepp
Actually we need to have a predictable tmpfile location (for the caching feature). The real issue is that it shouldn't be in /tmp as kjetilho said : kjetilho doesn't help if the attacker can do mkdir /tmp/subdir; chmod 777 /tmp/subdir after a reboot So, let's go for some directories created at

Bug#668536: munin: The tempfile location has to be predictable, but not creatable by anyone.

2012-04-13 Thread Helmut Grohne
On Fri, Apr 13, 2012 at 06:10:24PM +0200, Steve Schnepp wrote: Actually we need to have a predictable tmpfile location (for the caching feature). I did notice the caching feature even though I did not explicitly mention it in my initial bug report. The real issue is that it shouldn't be in

Bug#668536: [Packaging] Bug#668536: munin: The tempfile location has to be predictable, but not creatable by anyone.

2012-04-13 Thread Stig Sandbeck Mathisen
Helmut Grohne hel...@subdivi.de writes: So you already pointed out that we are talking about a cache, but still use /var/lib. Why? I suggested /var/cache/munin/graph and still think that it is a better place, because your backup solution does not need to back up those graphs. The different