• Bug#259246: acknowledged by developer (openwebmail: permissions)

    From Dariush Pietrzak@1:229/2 to Debian Bug Tracking System on Thu Aug 12 12:40:10 2004
    From: [email protected]

    On Thu, Aug 12, 2004 at 02:48:39AM -0700, Debian Bug Tracking System wrote:
    This is an automatic notification regarding your Bug report
    #259246: openwebmail: Package sets lots of web-accessible scripts suid-root, which was filed against the openwebmail package.

    It has been closed by one of the developers, namely
    "Sergio Rua" <[email protected]>.

    Their explanation is attached below. If this explanation is
    unsatisfactory and you have not received a better one in a separate
    message then please contact the developer, by replying to this email.

    Debian bug tracking system administrator
    (administrator, Debian Bugs database)

    Received: (at 259246-done) by bugs.debian.org; 12 Aug 2004 09:40:05 +0000 >From [email protected] Thu Aug 12 02:40:05 2004
    Return-path: <[email protected]>
    Received: from cm19098.red.mundo-r.com (server.netgalicia.com) [213.60.19.98]
    by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
    id 1BvC45-0004jC-00; Thu, 12 Aug 2004 02:40:05 -0700
    Received: from localhost (localhost [127.0.0.1])
    by server.netgalicia.com (Postfix) with ESMTP id BF5977B4E8
    for <[email protected]>; Thu, 12 Aug 2004 11:40:03 +0200 (CEST)
    Received: from server.netgalicia.com ([127.0.0.1])
    by localhost (server [127.0.0.1]) (amavisd-new, port 10024)
    with ESMTP id 03653-10 for <[email protected]>;
    Thu, 12 Aug 2004 11:40:03 +0200 (CEST)
    Received: by server.netgalicia.com (Postfix, from userid 110)
    id 992E07B4A0; Thu, 12 Aug 2004 11:40:03 +0200 (CEST)
    Received: from pattrynet.org (localhost [127.0.0.1])
    by server.netgalicia.com (Postfix) with ESMTP id CDFC67B4A0
    for <[email protected]>; Thu, 12 Aug 2004 11:39:58 +0200 (CEST)
    From: "Sergio Rua" <[email protected]>
    To: [email protected]
    Subject: openwebmail: permissions
    Date: Thu, 12 Aug 2004 11:39:58 +0100
    Message-Id: <[email protected]>
    X-Mailer: Open WebMail 2.30 20040103
    X-OriginatingIP: 212.159.2.3 (srua)
    MIME-Version: 1.0
    Content-Type: text/plain;
    charset=iso-8859-1
    X-Virus-Scanned: by amavisd-new-20030616-p5 (Debian) at netgalicia.com Delivered-To: [email protected]
    X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25
    (1.212-2003-09-23-exp) on spohr.debian.org
    X-Spam-Status: No, hits=-3.0 required=4.0 tests=BAYES_00 autolearn=no
    version=2.60-bugs.debian.org_2004_03_25
    X-Spam-Level:

    Hello,

    I am closing this bug because as far as I know, there is no way to use openwebmail without root permissions.
    It's been more then a year that I've been using openwebmail without root
    in multiple locations. I already described this setup.

    It needs to be root in advance to later on change the euid to the loged
    why would you want to change the euid to the loged user? This is webmail,
    it only needs to read and send mail.

    --
    Dariush Pietrzak,
    Key fingerprint = 40D0 9FFB 9939 7320 8294 05E0 BCC7 02C4 75CC 50D9


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Sergio Rua@1:229/2 to Dariush Pietrzak on Thu Aug 12 14:00:12 2004
    From: [email protected]

    Hello,

    On 12/Aug/2004, Dariush Pietrzak wrote:

    It's been more then a year that I've been using openwebmail without root
    in multiple locations. I already described this setup.

    I've tried and it didn't work at all.

    It needs to be root in advance to later on change the euid to the loged
    why would you want to change the euid to the loged user? This is webmail,
    it only needs to read and send mail.

    Because openwebmail reads and writes in Mailboxes. These mailboxes have
    an owner. Openwebmail do login, change the euid to the owner of the
    mailbox and continues working. In order to do that, it **needs** to be
    root. I am really don't know how you managed to make it working not
    beeing root.

    Could you detail your configuration and send me an 'ls -l' or you *.pl
    files?

    --
    Sergio

    The difference between a Miracle and a Fact is exactly the difference
    between a mermaid and a seal.
    -- Mark Twain


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)