Bug 13899 - msec report world writable files
Summary: msec report world writable files
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Remco Rijnders
QA Contact:
URL:
Whiteboard: mga4 too
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-12 01:21 CEST by Thomas Spuhler
Modified: 2015-01-10 18:03 CET (History)
1 user (show)

See Also:
Source RPM: spamassassin
CVE:
Status comment:


Attachments

Description Thomas Spuhler 2014-08-12 01:21:17 CEST
Description of problem:

Security Warning: World Writable files found :
- /var/spool/spamassassin
- /var/spool/spamassassin/auto-whitelist

Version-Release number of selected component (if applicable):
Current version 3.4.0

Spamassassin vr. 3.4 doesn't provide file auto-whitelist
Fedora doesn't even install this file. Maybe we can obsolete it too.


Reproducible: 

Steps to Reproduce:
Thomas Spuhler 2014-08-12 01:23:30 CEST

CC: (none) => thomas
Assignee: bugsquad => remi
Whiteboard: (none) => mga4 too

Comment 1 Rémi Verschelde 2014-08-12 08:04:11 CEST
You got the wrong Remmy ;-)

Assigning to Remco (he's not overly available as of late though, so I'd say feel free to fix the issue if you know how).

Assignee: remi => r+mageia

Remco Rijnders 2014-08-12 08:17:00 CEST

Status: NEW => ASSIGNED

Comment 2 Thomas Spuhler 2014-08-12 17:40:22 CEST
It looks like a lot of folks are making changes to this package. But I will try in cauldron first. This is used on servers, so we cannot break it.
Comment 3 Remco Rijnders 2014-08-17 19:06:52 CEST
@Thomas,

Thanks for the report. Use of these file permissions has been in the package since Mandriva 2007 (See https://qa.mandriva.com/show_bug.cgi?id=27424). That said, I don't think auto whitelisting is being used by default at all anymore in spamassassin. If one were to use auto whitelisting, I still think per user settings would be better than the global ones we have configured now. As such, I am going to update the package accordingly and take these files out completely.

Assignee: r+mageia => remco

Comment 4 Thomas Spuhler 2014-09-06 00:26:53 CEST
Remco,
I see you made the changes in cauldron. Are you going to make them in mga4 as well?
Comment 5 Thomas Spuhler 2014-11-01 00:27:07 CET
Ping
Comment 6 Thomas Spuhler 2015-01-10 18:03:23 CET
I guess this is fixed in mga4:

$ rpm -ql spamassassin
doesn't show the file anymore

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.