world writeable files



My nightly security report is showing me that esound and perhaps gdm? are creatubg world writeable directories and files within it.

Security Warning: World Writeable files found :
- /tmp/.esd
- /tmp/.esd/socket

[drfickle tp drfickle]$ ls -al /tmp/
total 48
drwxrwxrwt   10 root     root         4096 Feb  7 23:55 ./
drwxr-xr-x   22 root     root         4096 Feb  1 13:32 ../
drwxrwxrwt    2 root     root         4096 Feb  7 18:44 .ICE-unix/
-r--r--r--    1 root     drfickle       11 Feb  7 18:44 .X0-lock
drwxrwxrwt    2 root     gdm          4096 Feb  7 18:44 .X11-unix/
drwxrwxrwx    2 drfickle drfickle     4096 Feb  7 18:44 .esd/

[drfickle tp drfickle]$ ls -al /tmp/.esd/
total 8
drwxrwxrwx    2 drfickle drfickle     4096 Feb  7 18:44 ./
drwxrwxrwt   10 root     root         4096 Feb  7 23:55 ../
srwxrwxrwx    1 drfickle drfickle        0 Feb  7 18:44 socket=

[drfickle tp drfickle]$ ls -al /tmp/.X11-unix/
total 8
drwxrwxrwt    2 root     gdm          4096 Feb  7 18:44 ./
drwxrwxrwt   10 root     root         4096 Feb  7 23:55 ../
srwxrwxrwx    1 root     drfickle        0 Feb  7 18:44 X0

Are these bugs or am I missing something? I didn't see this topic covered on either gnome-list or this list by searching the archives on lists.gnome.org.

Thanks

--

Steve Fox
http://k-lug.com





[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]