Package: automysqlbackup
Version: 2.6+debian.3-1

Bug initially reported at
https://bugs.launchpad.net/ubuntu/+source/automysqlbackup/+bug/1251447

automysqlbackup creates its backup directory with world readable and
executable permissions, allowing any user to list all files, and any
permissions errors on the individual dump files may allow all users on the
system to inspect database dumps:

$ ls -lad / /var /var/lib /var/lib/automysqlbackup
drwxr-xr-x 24 root root 4096 Oct 29 18:23 /
drwxr-xr-x 13 root root 4096 Oct 29 18:24 /var
drwxr-xr-x 59 root root 4096 Nov 14 15:23 /var/lib
drwxr-xr-x 2 root root 4096 Feb 15 2012 /var/lib/automysqlbackup

Thanks

Attachment: signature.asc
Description: Digital signature

Reply via email to