man: Don't suggest making groupmems user-writeable
Suggesting mode 2770 is dangerous because it makes the binary writeable by all members of the owning group which is supposed to be normal end-users. Suggest 2710 instead as is usual for s[ug]id binaries, allowing execution but neither reading nor writing. Signed-off-by: Michael Weiser <michael.weiser@gmx.de>
This commit is contained in:
@@ -8878,14 +8878,14 @@ msgstr "EINRICHTUNG"
|
||||
|
||||
#: groupmems.8.xml:181(para)
|
||||
msgid ""
|
||||
"The <command>groupmems</command> executable should be in mode <literal>2770</"
|
||||
"The <command>groupmems</command> executable should be in mode <literal>2710</"
|
||||
"literal> as user <emphasis>root</emphasis> and in group <emphasis>groups</"
|
||||
"emphasis>. The system administrator can add users to group <emphasis>groups</"
|
||||
"emphasis> to allow or disallow them using the <command>groupmems</command> "
|
||||
"utility to manage their own group membership list."
|
||||
msgstr ""
|
||||
"Die ausführbare Datei <command>groupmems</command> sollte die Rechte "
|
||||
"<literal>2770</literal> haben und dem Benutzer <emphasis>root</emphasis> und "
|
||||
"<literal>2710</literal> haben und dem Benutzer <emphasis>root</emphasis> und "
|
||||
"der Gruppe <emphasis>groups</emphasis> gehören. Der Systemadministrator kann "
|
||||
"Benutzer der Gruppe <emphasis>groups</emphasis> hinzufügen, um ihnen zu "
|
||||
"ermöglichen, mit <command>groupmems</command> die Mitgliederliste ihrer "
|
||||
@@ -8896,14 +8896,14 @@ msgstr ""
|
||||
msgid ""
|
||||
"\n"
|
||||
"\t$ groupadd -r groups\n"
|
||||
"\t$ chmod 2770 groupmems\n"
|
||||
"\t$ chmod 2710 groupmems\n"
|
||||
"\t$ chown root.groups groupmems\n"
|
||||
"\t$ groupmems -g groups -a gk4\n"
|
||||
" "
|
||||
msgstr ""
|
||||
"\n"
|
||||
"\t$ groupadd -r groups\n"
|
||||
"\t$ chmod 2770 groupmems\n"
|
||||
"\t$ chmod 2710 groupmems\n"
|
||||
"\t$ chown root.groups groupmems\n"
|
||||
"\t$ groupmems -g groups -a gk4\n"
|
||||
" "
|
||||
|
Reference in New Issue
Block a user