[Libreoffice-bugs] [Bug 32763] New: Modification to the installed app is allowed without admin rights

bugzilla-daemon at freedesktop.org bugzilla-daemon at freedesktop.org
Fri Dec 31 19:05:35 CET 2010


https://bugs.freedesktop.org/show_bug.cgi?id=32763

           Summary: Modification to the installed app is allowed without
                    admin rights
           Product: LibreOffice
           Version: LibO 3.3.0 RC2
          Platform: Other
        OS/Version: Mac OS X (All)
            Status: NEW
          Severity: minor
          Priority: medium
         Component: Installation
        AssignedTo: libreoffice-bugs at lists.freedesktop.org
        ReportedBy: gantim at gmx.de


1. Copy the LibreOffice App to /Applications (/Programme on German system)
using a normal account without admin privileges

2. You get asked to enter admin account/pw, do this

3. Start the german language pack

4. Install German language pack

Result: The german language pack is installed, without getting asked for an
admin account and pw. This is wrong. The permissions inside the application
binary package seems to be set in a way that modifications are allowed for
non-admins, although installed using the admin account. This makes is possible
for trojans and viruses to modify the application LibreOffice using the
standard account.

Did not add l10n keyword, as this should be the fault of the main application,
not the language pack. For the language pack it would be right behavior to fail
or ask for admin privileges, so it will be additional work there after chmod is
set correctly in the main app.

-- 
Configure bugmail: https://bugs.freedesktop.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the Libreoffice-bugs mailing list