Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-19 Thread Christoph Anton Mitterer
On Tue, 2010-08-17 at 21:59 +0200, Julien Valroff wrote: They are reluctant on changing this. As far as I remember of a previous discussion, the current permissions were set after a real conscious decision. I'll have a look at this. Well I'd use -a,... Well, upstream use -p but that's

Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-17 Thread Julien Valroff
Le dimanche 15 août 2010 à 18:06:14 (+0200), Christoph Anton Mitterer a écrit : Date: Sun, 15 Aug 2010 18:06:14 +0200 From: Christoph Anton Mitterer cales...@scientia.net To: Debian Bug Tracking System sub...@bugs.debian.org Subject: Bug#593120: /var/lib/rkhunter/tmp/ should not be group

Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-17 Thread Christoph Anton Mitterer
On Tue, 2010-08-17 at 15:06 +0200, Julien Valroff wrote: As already suggested by the rkhunter documentation, the tmp-dir /var/lib/rkhunter/tmp/ should have tight permissions. The tmp directory keeps the default rights defined by upstream. Then we should perhaps try to get this done upstream

Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-17 Thread Julien Valroff
: Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable Reply-To: jul...@kirya.net Le dimanche 15 août 2010 à 18:06:14 (+0200), Christoph Anton Mitterer a écrit : Date: Sun, 15 Aug 2010 18:06:14 +0200 From: Christoph Anton Mitterer cales...@scientia.net To: Debian Bug Tracking

Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-17 Thread Julien Valroff
Le mardi 17 août 2010 à 21:25:30 (+0200), Christoph Anton Mitterer a écrit : Date: Tue, 17 Aug 2010 21:25:30 +0200 From: Christoph Anton Mitterer cales...@scientia.net To: 593...@bugs.debian.org Subject: Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable Reply-To: Christoph Anton

Bug#593120: /var/lib/rkhunter/tmp/ should not be group readable

2010-08-15 Thread Christoph Anton Mitterer
Package: rkhunter Version: 1.3.6-4 Severity: wishlist Hi. As already suggested by the rkhunter documentation, the tmp-dir /var/lib/rkhunter/tmp/ should have tight permissions. group-rights should be removed even for the root group IMO. As sysadmins may have deliberately removed this for some