Skip Menu |

Preferred bug tracker

Please visit the preferred bug tracker to report your issue.

This queue is for tickets about the Pod-Simple-Wiki CPAN distribution.

Report information
The Basics
Id: 39481
Status: resolved
Priority: 0/
Queue: Pod-Simple-Wiki

People
Owner: Nobody in particular
Requestors: SHLOMIF [...] cpan.org
Cc:
AdminCc:

Bug Information
Severity: Normal
Broken in: 0.09
Fixed in: (no value)



Subject: Pod-Simple-Wiki-0.09 contains world-writable files
[MSG] No '/home/shlomi/.cpanplus/custom-sources' dir, skipping custom sources [MSG] Fetching of Pod::Simple::Wiki successful The Pod-Simple-Wiki archive contains world-writable files Found World-writable-files: drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/ drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/bin/ -rw-rw-rw- 0/0 3993 2008-05-24 09:12 Pod-Simple-Wiki-0.09/bin/pod2wiki -rw-rw-rw- 0/0 1383 2008-05-24 09:47 Pod-Simple-Wiki-0.09/Changes drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/examples/ -rw-rw-rw- 0/0 3993 2008-05-24 09:13 Pod-Simple-Wiki-0.09/examples/pod2wiki.pl -rw-rw-rw- 0/0 652 2007-02-01 16:39 Pod-Simple-Wiki-0.09/examples/pod2wiki_simple.pl drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/lib/ drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/lib/Pod/ drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/lib/Pod/Simple/ drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/ -rw-rw-rw- 0/0 5294 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Confluence.pm -rw-rw-rw- 0/0 6225 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Kwiki.pm -rw-rw-rw- 0/0 7967 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Mediawiki.pm -rw-rw-rw- 0/0 5555 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Moinmoin.pm -rw-rw-rw- 0/0 8869 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Template.pm -rw-rw-rw- 0/0 5578 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Tiddlywiki.pm -rw-rw-rw- 0/0 4955 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Twiki.pm -rw-rw-rw- 0/0 4975 2008-05-24 08:56 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki/Usemod.pm -rw-rw-rw- 0/0 16335 2008-05-24 09:16 Pod-Simple-Wiki-0.09/lib/Pod/Simple/Wiki.pm -rw-rw-rw- 0/0 492 2007-02-01 16:39 Pod-Simple-Wiki-0.09/Makefile.PL -rw-rw-rw- 0/0 1045 2008-05-24 09:17 Pod-Simple-Wiki-0.09/MANIFEST -rw-rw-rw- 0/0 481 2008-05-24 09:20 Pod-Simple-Wiki-0.09/META.yml -rw-rw-rw- 0/0 1453 2007-02-01 16:39 Pod-Simple-Wiki-0.09/README drwxrwxrwx 0/0 0 2008-05-24 09:49 Pod-Simple-Wiki-0.09/t/ -rw-rw-rw- 0/0 413 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/00_00_load.t -rw-rw-rw- 0/0 2058 2008-05-23 18:05 Pod-Simple-Wiki-0.09/t/01_01_wiki_format.t -rw-rw-rw- 0/0 2073 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/01_02_wiki_head.t -rw-rw-rw- 0/0 7367 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/01_03_wiki_lists.t -rw-rw-rw- 0/0 2021 2008-05-23 18:05 Pod-Simple-Wiki-0.09/t/02_01_kwiki_format.t -rw-rw-rw- 0/0 2066 2008-05-23 18:18 Pod-Simple-Wiki-0.09/t/02_01_kwiki_head.t -rw-rw-rw- 0/0 7375 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/02_01_kwiki_lists.t -rw-rw-rw- 0/0 2038 2008-05-23 18:05 Pod-Simple-Wiki-0.09/t/03_01_usemod_format.t -rw-rw-rw- 0/0 2067 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/03_02_usemod_head.t -rw-rw-rw- 0/0 7325 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/03_03_usemod_lists.t -rw-rw-rw- 0/0 2172 2008-05-23 18:05 Pod-Simple-Wiki-0.09/t/04_01_twiki_format.t -rw-rw-rw- 0/0 2118 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/04_02_twiki_head.t -rw-rw-rw- 0/0 7605 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/04_03_twiki_lists.t -rw-rw-rw- 0/0 2137 2008-05-23 18:06 Pod-Simple-Wiki-0.09/t/05_01_mediawiki_format.t -rw-rw-rw- 0/0 2042 2007-08-25 19:55 Pod-Simple-Wiki-0.09/t/05_02_mediawiki_head.t -rw-rw-rw- 0/0 8480 2007-08-25 19:55 Pod-Simple-Wiki-0.09/t/05_03_mediawiki_lists.t -rw-rw-rw- 0/0 1924 2007-08-25 19:55 Pod-Simple-Wiki-0.09/t/05_04_mediawiki_links.t -rw-rw-rw- 0/0 2030 2008-05-23 18:06 Pod-Simple-Wiki-0.09/t/06_01_moinmoin_format.t -rw-rw-rw- 0/0 8726 2007-02-01 16:39 Pod-Simple-Wiki-0.09/t/06_03_moinmoin_lists.t -rw-rw-rw- 0/0 2050 2008-05-23 18:06 Pod-Simple-Wiki-0.09/t/07_01_tiddlywiki_format.t -rw-rw-rw- 0/0 1998 2007-08-25 18:15 Pod-Simple-Wiki-0.09/t/07_02_tiddlywiki_head.t -rw-rw-rw- 0/0 7348 2007-08-25 19:24 Pod-Simple-Wiki-0.09/t/07_03_tiddlywiki_lists.t -rw-rw-rw- 0/0 2027 2008-05-23 18:18 Pod-Simple-Wiki-0.09/t/08_01_confluence_format.t -rw-rw-rw- 0/0 2008 2008-05-23 18:17 Pod-Simple-Wiki-0.09/t/08_02_confluence_head.t -rw-rw-rw- 0/0 7336 2008-05-23 19:18 Pod-Simple-Wiki-0.09/t/08_03_confluence_lists.t Wrong.
Hi, Thanks for your feedback although I'm guessing that this is a machine generated report since there doesn't appear to be any human input in it. If so could you please add a little more context that might make the report more usable. * Why exactly are you reporting this? * What is the problem with world writeable files in a distro? * What is your proposed remedy? * Is this part of a cpan-testers initiative or a home grown effort? John. --
On Sun Sep 21 10:07:51 2008, JMCNAMARA wrote: Show quoted text
> > > Hi, > > Thanks for your feedback although I'm guessing that this is a
machine Show quoted text
> generated report since there doesn't appear to be any human input in
it. Actually, it was semi-machine generated. I pasted the output from a script after seeing the reports of the world-writable files in this distribution (and others) in msec. Show quoted text
> > If so could you please add a little more context that might make the > report more usable. > > * Why exactly are you reporting this? >
Because msec reports it after I'm smoking CPAN. Show quoted text
> * What is the problem with world writeable files in a distro?
Let's suppose Makefile.PL is world-writable. While the distro is being unpacked, a malicious user writes something like: {{{ system('rm -fr $HOME'); }}} to it, and after you come to the "perl Makefile.PL" stage - you lose your home-directory. ;-) In any case, Mandriva's msec warns about them, which bothers me. Show quoted text
> > * What is your proposed remedy?
Make sure none of the files in the archive are world-writable. Show quoted text
> > * Is this part of a cpan-testers initiative or a home grown effort? >
I'm a CPAN tester and run my testing under a different user. Then I'm getting reports that there are world-writable files in the directories created by the CPANPLUS, and so decided to report it whenever I encounter it. Regards, -- Shlomi Fish
Hi Shlomi Fish, Ok then. Thanks for that. I'll fix it in the next release. John. --
Fixed in version 0.11. Thanks, John. --