pcp
[Top] [All Lists]

[Bug 1062] mmv pmda sensitive to malevolent data

To: pcp@xxxxxxxxxxx
Subject: [Bug 1062] mmv pmda sensitive to malevolent data
From: bugzilla-daemon@xxxxxxxxxxx
Date: Thu, 30 Jun 2016 16:16:35 +0000
Auto-submitted: auto-generated
Delivered-to: pcp@xxxxxxxxxxx
In-reply-to: <bug-1062-835@xxxxxxxxxxxxxxxx/bugzilla/>
References: <bug-1062-835@xxxxxxxxxxxxxxxx/bugzilla/>

Comment # 4 on bug 1062 from
(In reply to comment #3)
> Targetted fuzzing of mmv input data is left as an interesting future QA
> extension.  [...] it is less of an issue with use
> of the group-based mmv stats dir access of course.

The group-based mmv stats dir is only a documentation artefact.  Current code
pcp/mmv retains the less-secure-by-default 1777 permissions for brand-new pcp
installations.


You are receiving this mail because:
  • You are on the CC list for the bug.
<Prev in Thread] Current Thread [Next in Thread>