Re: Vulnerability in pcs or is it in more generic code?
Paul Wise <[email protected]>
| Newsgroups | gmane.linux.debian.devel.lts,gmane.linux.debian.devel.security |
|---|---|
| Organization | Debian |
| Message-ID | <[email protected]> |
On Mon, 2022-09-05 at 21:38 +0200, Ola Lundqvist wrote: > I agree that it is good to fix the pcs package, but shouldn't we fix > the default umask in general? > I would argue that the default umask is insecure. bookworm login sets new user home directories to secure permissions: $ grep -E 'HOME_MODE\s*[0-9]' /etc/login.defs #HOME_MODE 0700 This somewhat mitigates, but not completely, the umask being insecure: $ grep -E 'UMASK\s*[0-9]' /etc/login.defs UMASK 022 I can't find any bugs open about changing the default umask, but it was mentioned in replies to the recent adduser thread: https://lists.debian.org/msgid-search/YieJALY0ny0+07pw-MEsB+WDYHc7QKvwJT6wXshvVK+yQ3ZXh@public.gmane.org -- bye, pabs https://wiki.debian.org/PaulWise
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEYQsotVz8/kXqG1Y7MRa6Xp/6aaMFAmMWnakACgkQMRa6Xp/6 aaOOXg/9FhVggWcmtOQqbJanScUB/3BE36I1MQYypr4jyIPkqZvwZ5mZ2AtNRz6+ aDaTT0F1EidmHXGZNi6Nkiq3CRLm5FAleVhLt1BzOYsqRa6F/p9dkYiGXDciOoZ7 EAZ8qimqDnT5F9CvpzDlJfZOHJSMgvsi7XZElLxkCuReOtEbD+9chGY3SLmK7Xvb B+9U5dxk85cR443yAtX6aOQUwsIJArhsn5bkePUOku+qJYYdNxVG5QXOkZ4j5oCM 3WN4r1Q+Z6ClRuiPSHl9OWBr38PLUUq3G4UOsAYgknY1ymIfqpC6R6ej5UyrIz51 dRocjxolC5U3aiWoZck6l6njwPhWOUIvRVL/WTf67R36fKuHXmOkOc4Hq54V7m4B p+TrGeTxnJ0tWk4Hcsb1mP/t9CrRR47sX+HMZbKin285nf64LGDcAgcnasWEju24 OVr9lG2/nGMcdnRLMdplNY292RyB6LG9fiZnFl9aog6fyTnoq/vp7/JB/CwKcSWl P5XliTEOrf4luFHQrujIdUewQC6lhtzQynapv2x8l7FWVIatQow9NWTN6zBqlR/x u6lZ5tmoD/bMZa6GdGlI/7DsatPi5N5A/oX4HCCxiNdC5M6pj8uQSapf6IPzykR+ BmtFm/TBVgd08WfbjYU8mps5F8mNBLQiLOUMJgtcPf+gcHovwas= =ujwc -----END PGP SIGNATURE-----