I hope someone from Mandrake is still reading this list. I got the advisary for the new kernel in my mail, and installed the new kernel. Since, then, any number of processes which used to write files that were writable only by themselves (leafnode as user news, mailman as user mail and so on) are now writing their files in a world readable setting. My security logs this morning started reporting files in /var/spool/news, /var/lock/subsys, /var/run, /var/lib/mailman/lists and so on as being writable. Checking those directories, I find sure enough that everything is -rw-rw-rw- -- clearly, this is not acceptable! Can someone please look into this and fix it and issue a new kernel? This needs to not continue to happen. When I su to the user IDs in question and do a umask command, I see 0022 like it should be - so I can't see any reason why this should be happening.
Thanks! --Dave -- David Guntner GEnie: Just say NO! http://www.akaMail.com/pgpkey/davidg or key server for PGP Public key
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com