[Secure-testing-team] Bug#815878: Creates backup folders world readable

Thomas Goirand zigo at debian.org
Thu Feb 25 09:31:41 UTC 2016


Package: ftpbackup
Version: 0.3-1
Severity: critical
Tags: security

As per Jakub's message in debian-devel:

> # create BACKUPHOME if not exists
> mkdir -p $BACKUPHOME

No umask set anywhere in this script, so in default setup the directory (and
later, the backup files) will be created readable to anyone.



More information about the Secure-testing-team mailing list