Notes Client for Linux: Insecure Installation Routine

Nov 23, 2007

The installation routine with Version 8 of Lotus Notes for Linux, which was released by IBM in September, leaves a whole bunch of files with read, write and executable permissions set for any user behind on the filesystem.

The Linux Client, which users can download from IBM for a 60-day trial after registering, is first copied to disk as a tarball, "C14SXEN.tar". While researching an article for Linux Magazine, our authors discovered incorrect permissions in the tarball when unpacked by root. This is caused by the "tar" command unpacking the archive and ignoring the umask set for the environment when called by root. This means that file permissions are set exactly as configured in the tar archive.

On starting the install, the wrapper script, "setup.sh", again sets the permissions for the installation script to 777, again wrecking the plans of security conscious admins:

01 #!/bin/sh
02 umask 022
03 chmod 777 "${0%setup.sh}/installdata"
04 "${0%setup.sh}/installdata" "$@"

The call to umask in line 3 makes the 200MB binary "installdata" script globally readable, writable and executable. This gives you a large file that anyone can edit that has to be run with root privileges for installations in multiuser environments.

Linux Magazine has informed the IBM developer team of the issue, and the bug was confirmed after a couple of tests. Work is in progress on a fix, says IBM.

Lotus Notes is the client for IBM’s Domino Server, a comprehensive database System for document management, groupware and integrated application development. The latest version, Version 8 is based on Eclipse, and this is also the first time that a full-fledged Linux desktop client has been available.

Related content

  • Lotus Notes 8 Available for Linux Servers

    IBM has now released the new version of the Lotus Notes Groupware and Collaboration Suite for Linux servers. Besides numerous enhancements and a new, Java-based architecture, the Red Hat Enterprise Linux 5 now provides a Linux distribution-based platform for the server.

  • IBM and Canonical Bring Netbook Software to Africa

    IBM has joined Canonical to market Ubuntu-based netbooks with IBM's Smart Work applications in emerging world markets. Africa is the beginning.

  • ASK KLAUS!

    Klaus Knopper is the creator of Knoppix and co-founder of the LinuxTag expo. He currently works as a teacher, programmer, and consultant. If you have a configuration problem, or if you just want to learn more about how Linux works, send your questions to: klaus@linux-magazine. com

  • SSL-Explorer

    SSL-Explorer provides an easy, web-based interface for configuring a virtual private network.

  • Adeona

    If you use a laptop, you have a good chance of having it lost or stolen. Learn about Adeona, a reliable open source system that can help you locate your lost or stolen laptop.

comments powered by Disqus