[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#201087: marked as done (apache should allow symlinks in cgi-bin)



Your message dated Thu, 14 Aug 2003 08:47:20 -0400
with message-id <E19nHVg-0005o8-00@auric.debian.org>
and subject line Bug#201087: fixed in apache 1.3.27.1-1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 11 Jul 2003 05:38:21 +0000
>From uwe@geordi.oche.de Fri Jul 11 00:38:10 2003
Return-path: <uwe@geordi.oche.de>
Received: from sundancer.oche.de [194.94.252.29] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 19aqbi-0003vg-00; Fri, 11 Jul 2003 00:38:10 -0500
Received: by sundancer.oche.de (Postfix, from userid 10)
	id 918AF51C13; Fri, 11 Jul 2003 07:38:04 +0200 (CEST)
Received: by geordi (Postfix, from userid 1000)
	id 1843D149CC; Fri, 11 Jul 2003 07:28:55 +0200 (CEST)
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="ISO-8859-15"
From: Uwe Kappe <uwe@geordi.oche.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: analog: Permission-Problem
X-Mailer: reportbug 2.18
Date: Fri, 11 Jul 2003 07:28:54 +0200
Message-Id: <20030711052855.1843D149CC@geordi>
Delivered-To: submit@bugs.debian.org
X-Spam-Status: No, hits=-5.0 required=4.0
	tests=HAS_PACKAGE
	version=2.53-bugs.debian.org_2003_06_27
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 2.53-bugs.debian.org_2003_06_27 (1.174.2.15-2003-03-30-exp)

Package: analog
Version: 2:5.32-4
Severity: normal

Hi,

when I call the URL "http://localhost/cgi-bin/anlgform.cgi"; I get this
Error:

   You don't have permission to access /cgi-bin/anlgform.cgi on this
   server.
     _________________________________________________________________

       
    Apache/1.3.27 Server at localhost Port 80

What's wrong. Where can I manage the permissions for analog?

Kind Regards
Uwe

-- System Information:
Debian Release: testing/unstable
Architecture: i386
Kernel: Linux geordi 2.4.19 #1 Wed Dec 4 20:50:49 CET 2002 i586
Locale: LANG=C, LC_CTYPE=de_DE@euro

Versions of packages analog depends on:
ii  debconf                       1.2.35     Debian configuration management sy
ii  libc6                         2.3.1-16   GNU C Library: Shared libraries an
ii  libgd2-noxpm                  2.0.12-2   GD Graphics Library version 2 (wit
ii  libjpeg62                     6b-8       The Independent JPEG Group's JPEG 
ii  libpcre3                      4.3-3      Philip Hazel's Perl 5 Compatible R
ii  libpng12-0                    1.2.5.0-4  PNG library - runtime
ii  perl                          5.8.0-17   Larry Wall's Practical Extraction 
ii  zlib1g                        1:1.1.4-12 compression library - runtime

-- debconf information:
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
	LANGUAGE = (unset),
	LC_ALL = (unset),
	LC_MESSAGES = "en_GB.UTF-8",
	LC_CTYPE = "de_DE@euro",
	LANG = "C"
    are supported and installed on your system.
perl: warning: Falling back to the standard locale ("C").
* analog/anlgform: true


---------------------------------------
Received: (at 201087-close) by bugs.debian.org; 14 Aug 2003 12:54:48 +0000
>From katie@auric.debian.org Thu Aug 14 07:54:48 2003
Return-path: <katie@auric.debian.org>
Received: from auric.debian.org [206.246.226.45] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 19nHcu-0004ah-00; Thu, 14 Aug 2003 07:54:48 -0500
Received: from katie by auric.debian.org with local (Exim 3.35 1 (Debian))
	id 19nHVg-0005o8-00; Thu, 14 Aug 2003 08:47:20 -0400
From: fabbione@fabbione.net (Fabio M. Di Nitto)
To: 201087-close@bugs.debian.org
X-Katie: $Revision: 1.35 $
Subject: Bug#201087: fixed in apache 1.3.27.1-1
Message-Id: <E19nHVg-0005o8-00@auric.debian.org>
Sender: Archive Administrator <katie@auric.debian.org>
Date: Thu, 14 Aug 2003 08:47:20 -0400
Delivered-To: 201087-close@bugs.debian.org

We believe that the bug you reported is fixed in the latest version of
apache, which is due to be installed in the Debian FTP archive:

apache-common_1.3.27.1-1_m68k.deb
  to pool/main/a/apache/apache-common_1.3.27.1-1_m68k.deb
apache-dev_1.3.27.1-1_m68k.deb
  to pool/main/a/apache/apache-dev_1.3.27.1-1_m68k.deb
apache-doc_1.3.27.1-1_all.deb
  to pool/main/a/apache/apache-doc_1.3.27.1-1_all.deb
apache-perl_1.3.27.1-1_m68k.deb
  to pool/main/a/apache/apache-perl_1.3.27.1-1_m68k.deb
apache-ssl_1.3.27.1-1_m68k.deb
  to pool/main/a/apache/apache-ssl_1.3.27.1-1_m68k.deb
apache_1.3.27.1-1.diff.gz
  to pool/main/a/apache/apache_1.3.27.1-1.diff.gz
apache_1.3.27.1-1.dsc
  to pool/main/a/apache/apache_1.3.27.1-1.dsc
apache_1.3.27.1-1_m68k.deb
  to pool/main/a/apache/apache_1.3.27.1-1_m68k.deb
apache_1.3.27.1.orig.tar.gz
  to pool/main/a/apache/apache_1.3.27.1.orig.tar.gz
libapache-mod-perl_1.27-5_m68k.deb
  to pool/main/a/apache/libapache-mod-perl_1.27-5_m68k.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 201087@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Fabio M. Di Nitto <fabbione@fabbione.net> (supplier of updated apache package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Wed, 13 Aug 2003 18:05:38 +0200
Source: apache
Binary: apache-dev apache apache-common apache-doc apache-perl libapache-mod-perl apache-ssl
Architecture: source m68k all
Version: 1.3.27.1-1
Distribution: unstable
Urgency: low
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Fabio M. Di Nitto <fabbione@fabbione.net>
Description: 
 apache     - Versatile, high-performance HTTP server
 apache-common - Support files for all Apache webservers
 apache-dev - Apache webserver development kit
 apache-doc - Apache webserver docs
 apache-perl - Versatile, high-performance HTTP server with Perl support
 apache-ssl - Versatile, high-performance HTTP server with SSL support
 libapache-mod-perl - Integration of perl with the Apache web server
Closes: 31592 32429 57316 63202 96859 114472 126632 132296 136260 139848 142213 142737 143806 144457 150853 151384 153104 165573 169104 170732 170759 172597 172883 187867 194334 199001 199059 199355 199964 200698 201087 201545 202812 202929 203095 203715 204016
Changes: 
 apache (1.3.27.1-1) unstable; urgency=low
 .
   * The "Yes, we know there is a new upstream release" upload.
   * (Fabio M. Di Nitto)
     - Applied patch to fix libperl debug path (Closes: #203715)
     - Switched templates to use po-debconf (Closes: #187867)
       Thanks to all the translators that have been so fast and responsive!
     - Added ServerTokens directive in the default config (Closes: #170732)
     - Nullified output of /etc/init.d/apache-ssl (Closes: #153104)
     - Added --norestart option to apacheconfig* (Closes: #126632)
     - Moved examples to apache-common
     - New Standard-Version: 3.6.0
     - lintian cleanup (only 2 overrides left)
     - We now link against libpthread (Closes: #199001, #203095)
     - Fixed the documentation hell (Closes: #144457, #139848, #143806)
     - More strict dependencies against apache-common
       (Closes: #199355, #199964, #202812, #202929, #204016)
     - Updated contrib tarball
     - Fixed apachessl.postinst (Closes: #199059)
     - libapache-mod-perl is now shipped with apache to be able to build
       all the apache-* packages in sync
     - apache-perl merge: now it will be built in sync with apache
       (Closes: #142737)
     - libapache-mod-perl now suggests apache-dev (Closes: #96859)
     - apache-perl now uses logrotate.d
     - apache-perl is now a standalone package
     - apache-perl-ctl shipped as a symlink to apache-perlctl
       to maintain a coherent name scheme
     - Fixed init scripts for apache, apache-ssl and apache-perl
       (Closes: #201545)
     - apache-ssl source is shipped in a proper and sane way
   * (Tollef Fog Heen)
     - Bump email_max in apache-ssl.ssleay.cnf to 255 (Closes: #150853)
     - Only remove the old conffiles in /etc/apache and /etc/cron.d if
       they are unchanged.  (Closes: #194334, #169104)
     - Start debhelperizing a little, includes using debhelper for the
       restart stuff, so close the bugs related to apache not restarting
       properly.  (Closes: #136260, #172883, #142213)
     - Run apachectl configtest before restarting.  (Closes: #114472, #63202)
     - s/Handlers/Handles/ in 500mod_roaming.info (Closes: #165573)
     - Uncrackify proxy_ftp.c (Closes: #57316)
   * (Thom May)
     - Set LockFile for Apache-SSL so it doesn't conflict with Apache's
       (Closes: #170759)
     - Fix segfault on ia64 (Thanks to dann frazier <dannf@hp.com>)
       (Closes: #200698)
     - Make logrotate rotate log files with 644 permissions. (Closes: #132296)
     - Add notes to Readme.Debian regarding to the change of rotation perms,
       and also about how to make mod_auth_system work right. (Closes: #32429)
     - Add SymLinksIfOwnerMatch for cgi-bin (Closes: #201087)
     - Fixup apxs to detect how it's called and modify the correct config
       (Closes: #31592)
     - Fix up apache to respect a SHOULD in 2616 (Closes: #151384)
     - Turn off UseCanonicalName - it's a fairly advanced option and most
       users will not need it, or will only need it for certain VirtualHosts at
       worse. (Closes: #172597)
Files: 
 2f49dfb8efe2341fd6992e9d0841a5d6 990 web optional apache_1.3.27.1-1.dsc
 6ed3ad678b6b9518d24178eec1a78894 2990444 web optional apache_1.3.27.1.orig.tar.gz
 d4a75af740b3ac30799e8baf280a98f6 407621 web optional apache_1.3.27.1-1.diff.gz
 522de38abea8310c6477dde913b6f449 1040462 doc optional apache-doc_1.3.27.1-1_all.deb
 6e04a163b8e5684ee90a645aca9df275 344114 web optional apache_1.3.27.1-1_m68k.deb
 496ee971c40d1b11f2317dd425b8ef21 390548 web optional apache-ssl_1.3.27.1-1_m68k.deb
 8d819c7b29457b68666f843b84427e52 400390 web extra apache-perl_1.3.27.1-1_m68k.deb
 f15c37f2cdb8b3536d297079428962da 1595820 devel extra apache-dev_1.3.27.1-1_m68k.deb
 dfda14a7f1925527b59fbe893d5685af 820036 web optional apache-common_1.3.27.1-1_m68k.deb
 20e3e5fda759b20936fc85f17a97dd32 468162 web optional libapache-mod-perl_1.27-5_m68k.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE/O316hCzbekR3nhgRAsfkAJwPaxdy+EU5Q3n+TmkFBbcjJfRFfwCdHMx4
53G7nMTmsadR6FM8jAF3q88=
=cafO
-----END PGP SIGNATURE-----



Reply to: