FS#28994 - [w3m] documenation is installed with executable bit set
Attached to Project:
Arch Linux
Opened by Markus Dittrich (markusle) - Sunday, 18 March 2012, 19:57 GMT
Last edited by Gaetan Bisson (vesath) - Monday, 19 March 2012, 04:14 GMT
Opened by Markus Dittrich (markusle) - Sunday, 18 March 2012, 19:57 GMT
Last edited by Gaetan Bisson (vesath) - Monday, 19 March 2012, 04:14 GMT
|
Details
Description:
Currently, w3m installs its documentation with executable bit set which is not good and a potential security risk - mode 644 would be better. # ls -la /usr/share/doc/w3m total 208K drwxr-xr-x 2 root root 4.0K Feb 6 20:24 . drwxr-xr-x 121 root root 4.0K Mar 18 13:36 .. -rwxr-xr-x 1 root root 11K Feb 6 20:24 FAQ.html -rwxr-xr-x 1 root root 66K Feb 6 20:24 HISTORY -rwxr-xr-x 1 root root 2.6K Feb 6 20:24 keymap.default -rwxr-xr-x 1 root root 2.6K Feb 6 20:24 keymap.lynx -rwxr-xr-x 1 root root 16K Feb 6 20:24 MANUAL.html -rwxr-xr-x 1 root root 1.1K Feb 6 20:24 menu.default -rwxr-xr-x 1 root root 1.1K Feb 6 20:24 menu.submenu -rwxr-xr-x 1 root root 3.2K Feb 6 20:24 README -rwxr-xr-x 1 root root 1.8K Feb 6 20:24 README.cookie -rwxr-xr-x 1 root root 6.0K Feb 6 20:24 README.cygwin -rwxr-xr-x 1 root root 1.8K Feb 6 20:24 README.dict -rwxr-xr-x 1 root root 5.3K Feb 6 20:24 README.func -rwxr-xr-x 1 root root 6.9K Feb 6 20:24 README.img -rwxr-xr-x 1 root root 15K Feb 6 20:24 README.m17n -rwxr-xr-x 1 root root 1.4K Feb 6 20:24 README.mouse -rwxr-xr-x 1 root root 749 Feb 6 20:24 README.passwd -rwxr-xr-x 1 root root 1.5K Feb 6 20:24 README.pre_form -rwxr-xr-x 1 root root 1.7K Feb 6 20:24 README.tab -rwxr-xr-x 1 root root 9.3K Feb 6 20:24 STORY.html -rwxr-xr-x 1 root root 4.5K Feb 6 20:24 w3m.1 Additional info: * package version(s) # pacman -Qs w3m local/w3m 0.5.3-3 Text-based Web browser, as well as pager Steps to reproduce: always |
This task depends upon
Closed by Gaetan Bisson (vesath)
Monday, 19 March 2012, 04:14 GMT
Reason for closing: Fixed
Additional comments about closing: in SVN
Monday, 19 March 2012, 04:14 GMT
Reason for closing: Fixed
Additional comments about closing: in SVN
Comment by Gaetan Bisson (vesath) -
Monday, 19 March 2012, 04:08 GMT
This is *not* a security risk... Please, stop using buzzwords you
do not understand.