Notes Client for Linux: Insecure Installation Routine
The installation routine with Version 8 of Lotus Notes for Linux, which was released by IBM in September, leaves a whole bunch of files with read, write and executable permissions set for any user behind on the filesystem.
The Linux Client, which users can download from IBM for a 60-day trial after registering, is first copied to disk as a tarball, "C14SXEN.tar". While researching an article for Linux Magazine, our authors discovered incorrect permissions in the tarball when unpacked by root. This is caused by the "tar" command unpacking the archive and ignoring the umask set for the environment when called by root. This means that file permissions are set exactly as configured in the tar archive.
On starting the install, the wrapper script, "setup.sh", again sets the permissions for the installation script to 777, again wrecking the plans of security conscious admins:
01 #!/bin/sh
02 umask 022
03 chmod 777 "${0%setup.sh}/installdata"
04 "${0%setup.sh}/installdata" "$@"
The call to umask in line 3 makes the 200MB binary "installdata" script globally readable, writable and executable. This gives you a large file that anyone can edit that has to be run with root privileges for installations in multiuser environments.
Linux Magazine has informed the IBM developer team of the issue, and the bug was confirmed after a couple of tests. Work is in progress on a fix, says IBM.
Lotus Notes is the client for IBM’s Domino Server, a comprehensive database System for document management, groupware and integrated application development. The latest version, Version 8 is based on Eclipse, and this is also the first time that a full-fledged Linux desktop client has been available.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Gnome Fans Everywhere Rejoice for the Latest Release
Gnome 47.2 is now available for general use but don't expect much in the way of newness, as this is all about improvements and bug fixes.
-
Latest Cinnamon Desktop Releases with a Bold New Look
Just in time for the holidays, the developer of the Cinnamon desktop has shipped a new release to help spice up your eggnog with new features and a new look.
-
Armbian 24.11 Released with Expanded Hardware Support
If you've been waiting for Armbian to support OrangePi 5 Max and Radxa ROCK 5B+, the wait is over.
-
SUSE Renames Several Products for Better Name Recognition
SUSE has been a very powerful player in the European market, but it knows it must branch out to gain serious traction. Will a name change do the trick?
-
ESET Discovers New Linux Malware
WolfsBane is an all-in-one malware that has hit the Linux operating system and includes a dropper, a launcher, and a backdoor.
-
New Linux Kernel Patch Allows Forcing a CPU Mitigation
Even when CPU mitigations can consume precious CPU cycles, it might not be a bad idea to allow users to enable them, even if your machine isn't vulnerable.
-
Red Hat Enterprise Linux 9.5 Released
Notify your friends, loved ones, and colleagues that the latest version of RHEL is available with plenty of enhancements.
-
Linux Sees Massive Performance Increase from a Single Line of Code
With one line of code, Intel was able to increase the performance of the Linux kernel by 4,000 percent.
-
Fedora KDE Approved as an Official Spin
If you prefer the Plasma desktop environment and the Fedora distribution, you're in luck because there's now an official spin that is listed on the same level as the Fedora Workstation edition.
-
New Steam Client Ups the Ante for Linux
The latest release from Steam has some pretty cool tricks up its sleeve.