Comment 3 for bug 7004

Revision history for this message
In , Matt Zimmerman (mdz) wrote : Re: Bug#258847: libpisock8: System serial device permissions overridden

severity 258847 grave
thanks

On Sun, Jul 11, 2004 at 10:10:02PM +0200, David Pettersson wrote:
> Package: libpisock8
> Version: 0.11.8-10
> Severity: normal
> Tags: security
>
> Hi,
>
> The libpisock8 package places a libpisock8 file in the /etc/devfs/conf.d
> directory, which explicitly overrides the system permissions for the
> first serial port, setting /dev/ttyS0 to world read/writable.
>
> This is a nice convenience feature for the average user, but it also
> allows all users (even those not in the dialout group) to access the
> serial port.
>
> I am unsure how to solve this. However, please let me know if I can
> assist in any way.

This is a serious issue; I am adjusting the severity of this bug accordingly.

--
 - mdz