Mailbox vulnerable?

Hongwei Li hongwei at
Mon Jun 28 13:57:06 UTC 2004


We have a fc1 box.  We have he permissions setting as:

# ls -ld /var/spool/mail
drwxrwxr-x  2 root mail 4096 Jun 28 08:43 /var/spool/mail
# ls -ld /tmp
drwxrwxrwt  11 root root 24576 Jun 28 08:43 /tmp

The LogWatch always shows the warning:

Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

When a regular user (except root) opens pine to read mails, he also sees
this message at the very beninning for about 1 to 2 seconds.  As I
understand, the permission drwxrwxr-x is correct.   What is wrong?  Do I
need to change the permission on the mail directory? if yes, change it to



