Your message dated Sun, 19 Mar 2006 19:36:43 +0100
with message-id <[EMAIL PROTECTED]>
and subject line Answer of the maintainer
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: asciijump
Version: 0.0.6-1
Severity: important
Tags: security

Hello asciijump maintainer,
asciijump postinst include:

install -d -m 777 /var/games/asciijump

This has the effect of making /var/games/asciijump world-writable,
which is a security concern on a multi-user system.
This can be used to escape quotas, crash the system by overflowing the
/var partitions, hide files, triggereing buffer overflow in the code
that read the file in /var/games/asciijump that would not be otherwise
possible to exploit and other nasty things.

Debian policy documents a way to avoid that:
make /var/games/asciijump writable only by group 'games' (or
'asciijump') and make asciijump sgid 'games' (or 'asciijump').

Cheers,
-- 
Bill. <[EMAIL PROTECTED]>

Imagine a large red swirl here. 


--- End Message ---
--- Begin Message ---
I have adopted the package and i have forgotten to answer the NMUs, one
NMU was anyway done by me - i close the bugs no!

--- End Message ---

Reply via email to