[Bug 727971] AUDIT-0: server:search/mlocate for security impacts
https://bugzilla.novell.com/show_bug.cgi?id=727971 https://bugzilla.novell.com/show_bug.cgi?id=727971#c2 --- Comment #2 from Tomáš Chvátal <tchvatal@suse.com> 2011-11-03 11:35:22 UTC --- Locate stores the data in /var/lib/mlocate/ which is accessible only by the group and root. Preventing users from raw reading the database only root can access it. The app itself knows if the user has perms to view some file or not. Example: scarabeus@arcarius: ~ $ locate generate_gold.sh scarabeus@arcarius: ~ $ su - Heslo: root@arcarius: ~ # locate generate_gold.sh /root/generate_gold.sh -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com