Package: mgetty-fax
Version: 1.1.33-1
Severity: normal

The man pages says:

  -u <user name>
    Do  not  use the current user ID for authentication purposes but the
    user name specified. Since this can lead to easy  breach  of security,
    only "trusted" users  may use this flag. Currently, those users are
    "root", "lp" and "daemon" (hardwired into  the code).  Note: the status
    mail will still go to the user running faxspool(1) unless changed with
    "-f".

However, in the code, only root (ROOT_UID) is allowed to specify the -u
option.

When using faxspool as a backend through a print service (lprng in this
case), this breaks things for ordinary users, since the job will always be
owned by daemon, and the user cannot remove it.

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (100, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.4.27
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)

Versions of packages mgetty-fax depends on:
ii  cron                        3.0pl1-86    management of regular background p
ii  debconf                     1.4.30.13    Debian configuration management sy
ii  libc6                       2.3.2.ds1-21 GNU C Library: Shared libraries an
ii  mgetty                      1.1.33-1     Smart Modem getty replacement

-- debconf information:
* mgetty-fax/new_security_scheme:
* mgetty-fax/start_faxrunqd: false


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to