LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux From Scratch
User Name
Password
Linux From Scratch This Forum is for the discussion of LFS.
LFS is a project that provides you with the steps necessary to build your own custom Linux system.

Notices


Reply
  Search this Thread
Old 11-13-2015, 07:12 PM   #1
re_nelson
Member
 
Registered: Oct 2011
Location: Texas, USA
Distribution: LFS-SVN, Gentoo~amd64, CentOS-7, Slackware64-current, FreeBSD-11.1, Arch
Posts: 229

Rep: Reputation: Disabled
procmail perms (BLFS)


Although I am strongly considering using maildrop as a replacement for the BLFS default local mail delivery agent for fetchmail, I've been reading up further on the venerable procmail tool.

It's been essentially abandoned upstream for a decade and a half. Some see it as finished product in need of no further maintenance but the Debian-based distros have released at least 25 patches, some of which tackle vulnerabilities cited by CVE.

At minimum, my take is that BLFS installs it (using the "make install-suid" target) with permissions that are too wide open. Before I make the possible jump to maildrop, I've found these perms to be sufficient for both of /usr/bin/{procmail,lockfile}:

02511

Since both binaries are under the group mail and /var/mail is writable by that group, it makes sense to restrict the perms.

Any thoughts to the contrary?

Last edited by re_nelson; 11-13-2015 at 07:14 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CHMOD now perms for nothing duryodhan Slackware 7 10-18-2006 01:31 PM
changing perms on hd bernstein DamnSmallLinux 6 04-04-2005 09:47 PM
cdrw perms doralsoral Linux - Software 0 05-06-2004 10:26 PM
ripperX perms doralsoral Linux - Software 5 05-02-2004 11:22 AM
Is it safe to use those perms ? Punker51 Linux - Newbie 2 12-07-2003 09:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux From Scratch

All times are GMT -5. The time now is 10:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration