oss-sec mailing list archives

Re: CVE request: psi+ stores the cache file as world-readable


From: gremlin () gremlin ru
Date: Wed, 27 Feb 2013 07:41:28 +0400

On 26-Feb-2013 23:04:24 +0100, Agostino Sarubbo wrote:

Psi+, a fork of psi, stores its files in ~/.cache/psi+ as
world-readable.

That's normal - users' home directories are normally accessible
only by users themselves, and never by othe users:

gremlin@hren:~ > ls -ld .
drwx-----x 47 gremlin users 20480 2013-02-26 17:48 ./

This is the most loosy home directory mode I use - that's for
accessing ~/www by httpd. Even there I use umask 027 and at
other (non-http) servers it's 077.

Also, please check the umask setting in this case - I guess
psi+ respects it when creating files.


-- 
Alexey V. Vissarionov aka Gremlin from Kremlin <gremlin ПРИ gremlin ТЧК ru>
GPG key ID: 0xEF3B1FA8, keyserver: hkp://subkeys.pgp.net
GPG key fingerprint: 8832 FE9F A791 F796 8AC9 6E4E 909D AC45 EF3B 1FA8


Current thread: