Should "rnews" be useable to inject news by non-news users?

Jonathan Kamens jik at kamens.brookline.ma.us
Tue Jun 5 12:45:54 UTC 2001


Should users besides "news" be able to inject news with "rnews".

I'm asking because they can't, at least not in the inn that's shipped
with RedHat, and I think that they should be, so I'm trying to
understand if there's any reason why they shouldn't.

The reason they can't is that rnews is setuid "uucp" instead of setuid
"news", and/var/spool/news/incoming is owned by "news" rather than
"uucp".

I fixed this by making rnews setgid and /var/spool/news/incoming
group-writable, but I'd like to know if there are any reasons why
something like this shouldn't be the default configuration.

Thanks,

  jik


More information about the inn-bugs mailing list