Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments


price comparison with idealo.com
Price comparison for:
fast servers for your business solution, fast notebooks for long flights, software for good results, TomTom navigation systems, PC hardware, Plasma and LCD TVs, Computer Hardware and Software, MP3 Player, highend Laptops and many more. Get reviews of your favourite digital camera or  of  new dvd-players.

user friendly

  linux-magazine.com » Online » News » Notes Client for Linux: Insecure Installation Routine  

Print this page. Recommend
Slashdot it! Delicious Digg

Notes Client for Linux: Insecure Installation Routine

The installation routine with Version 8 of Lotus Notes for Linux, which was released by IBM in September, leaves a whole bunch of files with read, write and executable permissions set for any user behind on the filesystem.

The Linux Client, which users can download from IBM for a 60-day trial after registering, is first copied to disk as a tarball, "C14SXEN.tar". While researching an article for Linux Magazine, our authors discovered incorrect permissions in the tarball when unpacked by root. This is caused by the "tar" command unpacking the archive and ignoring the umask set for the environment when called by root. This means that file permissions are set exactly as configured in the tar archive.

On starting the install, the wrapper script, "setup.sh", again sets the permissions for the installation script to 777, again wrecking the plans of security conscious admins:

01 #!/bin/sh
02 umask 022
03 chmod 777 "${0%setup.sh}/installdata"
04 "${0%setup.sh}/installdata" "$@"

The call to umask in line 3 makes the 200MB binary "installdata" script globally readable, writable and executable. This gives you a large file that anyone can edit that has to be run with root privileges for installations in multiuser environments.

Linux Magazine has informed the IBM developer team of the issue, and the bug was confirmed after a couple of tests. Work is in progress on a fix, says IBM.

Lotus Notes is the client for IBM’s Domino Server, a comprehensive database System for document management, groupware and integrated application development. The latest version, Version 8 is based on Eclipse, and this is also the first time that a full-fledged Linux desktop client has been available.

(Markus Feilner)

Comments


Print this page. Recommend
Slashdot it! Delicious Digg
Related Articles
Linuxworld: IBM and Novell to Co-market Application Server
Gartner: IBM’s Blue Cloud Needs to Mature
Lotus Notes 8 Available for Linux Servers
Security Issues with IBM DB2 Database
Completely Fair Scheduler Analyzed
Linux Server Market Continues to Grow
Wherever you go...

...Linux Magazine goes with you!

Check out the advantages of a Digital Subscription:

  • Access articles by downloading PDFs,
  • find the Linux solutions you need with an easy keyword search,
  • maintain your own paperless archive...

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2008 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux-Nachrichten] [Linux Events]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Darmowe Programy Poland] [Open Source DVD Poland] [Linux Magazin Romania]
International: [Linux Magazine Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]