Print this page. Recommend
Slashdot it! Delicious Digg

Notes Client for Linux: Insecure Installation Routine

Nov 23, 2007

The installation routine with Version 8 of Lotus Notes for Linux, which was released by IBM in September, leaves a whole bunch of files with read, write and executable permissions set for any user behind on the filesystem.

The Linux Client, which users can download from IBM for a 60-day trial after registering, is first copied to disk as a tarball, "C14SXEN.tar". While researching an article for Linux Magazine, our authors discovered incorrect permissions in the tarball when unpacked by root. This is caused by the "tar" command unpacking the archive and ignoring the umask set for the environment when called by root. This means that file permissions are set exactly as configured in the tar archive.

On starting the install, the wrapper script, "setup.sh", again sets the permissions for the installation script to 777, again wrecking the plans of security conscious admins:

01 #!/bin/sh
02 umask 022
03 chmod 777 "${0%setup.sh}/installdata"
04 "${0%setup.sh}/installdata" "$@"

The call to umask in line 3 makes the 200MB binary "installdata" script globally readable, writable and executable. This gives you a large file that anyone can edit that has to be run with root privileges for installations in multiuser environments.

Linux Magazine has informed the IBM developer team of the issue, and the bug was confirmed after a couple of tests. Work is in progress on a fix, says IBM.

Lotus Notes is the client for IBM’s Domino Server, a comprehensive database System for document management, groupware and integrated application development. The latest version, Version 8 is based on Eclipse, and this is also the first time that a full-fledged Linux desktop client has been available.

(Markus Feilner)

Comments


Print this page. Recommend
Slashdot it! Delicious Digg
Related Articles
Completely Fair Scheduler Analyzed
Linux Foundation Prepares Linux for IPv6
Linux Server Market Continues to Grow
Linux Supercomputer Roadrunner Takes Petaflops Hurdle
Vulnerability in GNU "tar"
IBM's New IT Standards Policy: ISO Is Not Exclusive
Live Streaming of LISA '08

22nd Large Installation System Administration Conference

If you follow the fortunes of large installation IT, tune in on November 12-14 for a front row ticket to the Invited Talks series of the USENIX LISA conference.

Find out more

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]