[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#252627: apache: environment cleaning not useful



severity 252627 wishlist
tags 252627 wontfix
stop

On Fri, 4 Jun 2004, Richard W.M. Jones wrote:

> Package: apache
> Version: 1.3.29.0.2-4
> Severity: normal
>
> After getting the latest Apache, I found that passing environment
> variables to the server from the command line no longer works.  This
> is the changelog:
>
>     - More init scripts cleanup. It shouldn't leak environment information
>       (Closes: #229653, #230991)
>
> Unfortunately this isn't very useful behaviour.  I routinely set
> PGHOST to select development database.  Now there is no useful way to
> pass this from the command line to Apache.  (Adding it to
> /etc/apache/local.conf using SetEnv doesn't work because mod_env runs
> too late).
>
> As another example it makes the PassEnv directive completely useless.
>

Leaking environment information can disclose sensible information about
the server. This bug will not be fixed.

Fabio

-- 
<user> fajita: step one
<fajita> Whatever the problem, step one is always to look in the error log.
<user> fajita: step two
<fajita> When in danger or in doubt, step two is to scream and shout.



Reply to: