Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Notes Client for Linux: Insecure Installation Routine

Nov 23, 2007

The installation routine with Version 8 of Lotus Notes for Linux, which was released by IBM in September, leaves a whole bunch of files with read, write and executable permissions set for any user behind on the filesystem.

The Linux Client, which users can download from IBM for a 60-day trial after registering, is first copied to disk as a tarball, "C14SXEN.tar". While researching an article for Linux Magazine, our authors discovered incorrect permissions in the tarball when unpacked by root. This is caused by the "tar" command unpacking the archive and ignoring the umask set for the environment when called by root. This means that file permissions are set exactly as configured in the tar archive.

On starting the install, the wrapper script, "setup.sh", again sets the permissions for the installation script to 777, again wrecking the plans of security conscious admins:

01 #!/bin/sh
02 umask 022
03 chmod 777 "${0%setup.sh}/installdata"
04 "${0%setup.sh}/installdata" "$@"

The call to umask in line 3 makes the 200MB binary "installdata" script globally readable, writable and executable. This gives you a large file that anyone can edit that has to be run with root privileges for installations in multiuser environments.

Linux Magazine has informed the IBM developer team of the issue, and the bug was confirmed after a couple of tests. Work is in progress on a fix, says IBM.

Lotus Notes is the client for IBM’s Domino Server, a comprehensive database System for document management, groupware and integrated application development. The latest version, Version 8 is based on Eclipse, and this is also the first time that a full-fledged Linux desktop client has been available.

(Markus Feilner)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
Security Issues with IBM DB2 Database
Completely Fair Scheduler Analyzed
Linux Foundation Prepares Linux for IPv6
Open Group Publishes New Documents to Assist SOA
Linux Server Market Continues to Grow
Linux Supercomputer Roadrunner Takes Petaflops Hurdle
Special Linux Magazine 3 for 1 Offer

Get 3 Issues + 3 DVDs for the price of a single issue!

Let Linux Magazine's hands-on, technical articles guide you in your daily Linux use. Check out bonus DVDs like Ubuntu, SUSE, or Fedora and save the download.

Only available for a limited time. Don't miss out!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2010 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]