Bug#313644: zope2.7: Local security bug

2005-06-14 Thread martin f krafft
tags 313644 + patch security severity 313644 important thanks Please try this patch: --- /usr/lib/zope2.7/bin/mkzopeinstance.py.orig 2005-06-14 22:28:04.538426375 +0200 +++ /usr/lib/zope2.7/bin/mkzopeinstance.py 2005-06-14 22:23:28.145889036 +0200 @@ -147,7 +147,7 @@ print 'User/passw

Bug#313644: zope2.7: Local security bug

2005-06-14 Thread Dmitry E. Oboukhov
Package: zope2.7 Severity: grave Justification: user security hole uvw.ru:[/home/dimka]# umask 022 uvw.ru:[/home/dimka]# mkzope2.7instance ... [skipped] ... Directory: /tmp/testmkzope ... [skipped] uvw.ru:[/home/dimka]# ls -lR /tmp/testmkzope|grep inituser -rw-r--r-- 1 root root 40 2005-06-