From: Wybo Dekker Date: 2012-07-26T19:21:19+09:00 Subject: Re: rubyzip gem overwrites write-protected root-owned file On 2012-07-24 16:44, Quintus wrote: > Am 24.07.2012 14:44, schrieb Wybo Dekker: >> I'm playing with the rubyzip gem, and found, with this little script: >> >> require 'rubygems' >> require 'zip/zip' >> Zip::ZipFile.open('test.zip', Zip::ZipFile::CREATE) do |zipfile| >> zipfile.add('rgb.txt','/etc/X11/rgb.txt') >> end >> >> that 'test.zip' is written without any warning, even if it exists, is >> root-owned and write-protected. Is that a bug? > > If you can overwrite a root-owned file not writable by neither a group > you’re in nor for others (i.e. something like rw------- root:root), then > you have a serious security problem (which has nothing to do with Ruby). > Check your system settings (and you’re sure you don’t run this as root?). Well, if I try to add a file using the system zip, I am not allowed to do so: $ zip test.zip /etc/passwd zip I/O error: Permission denied zip error: Could not create output file (test.zip) So what I think happens is that Rubyzip, instead of adding a file to the zip, as requested, creates a new zip, deletes the old one (which is allowed in a directory which I own) and the renames the new zip to the old filename, thus effectively removing the old zip's ownership and permissions. I think that is not how it should work... -- Wybo