Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#23367 - [attr] files are owned by 'nobody:nobody'

Attached to Project: Arch Linux
Opened by Mathijs Kwik (bluescreen303) - Sunday, 20 March 2011, 17:24 GMT
Last edited by Allan McRae (Allan) - Sunday, 20 March 2011, 22:34 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To Allan McRae (Allan)
Architecture x86_64
Severity Critical
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

it seems that (at least on x86_64) the files belonging to the xattr packages are owned by:
user nobody
group nobody

and permissions are 644/755, making them writable for user nobody.
since nobody is mostly used for daemons and to allow anonymous access, this is a potential security risk.

This task depends upon

Closed by  Allan McRae (Allan)
Sunday, 20 March 2011, 22:34 GMT
Reason for closing:  Fixed
Additional comments about closing:  attr-2.4.44-3
Comment by Greg (dolby) - Sunday, 20 March 2011, 22:14 GMT
Same in i686

Loading...