Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <952139437.70461257782995434.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 9 Nov 2009 11:09:55 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
Subject: X server umask issue

Hi everyone,

I'm looking for a second opinion, and wondering if anyone has some extra insight
into this Debian bug:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555308

It seems that the suid X server inherits the users umask, and if you have a umask
of 0, the X log file will end up being world writable. This is obviously a very
silly thing to do anyhow, so I question if that's a security flaw itself. It is a
bug that should probably be fixed I'd say.

What I am wondering though, are there other files the X server creates that could
be an issue for this? I'm not aware of any, but I'm also not an expert by any
stretch of the imagination. Am I missing something else?

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.