[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#264622: marked as done (apache2-common: /var/cache/apache2 has wrong permissions)



Your message dated Tue, 31 Aug 2004 15:03:01 +1000
with message-id <001c01c48f17$cb93fe30$6400a8c0@int.trinitysoftware.com.au>
and subject line Bug closures
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 9 Aug 2004 17:06:12 +0000
>From esteve@sindominio.net Mon Aug 09 10:06:12 2004
Return-path: <esteve@sindominio.net>
Received: from 27.red-80-37-183.pooles.rima-tde.net (itchy.ratonera) [80.37.183.27] 
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1BuDbA-0001jj-00; Mon, 09 Aug 2004 10:06:12 -0700
Received: by itchy.ratonera (Postfix, from userid 1000)
	id 21FED7D05; Mon,  9 Aug 2004 19:03:13 +0200 (CEST)
Date: Mon, 9 Aug 2004 19:03:13 +0200
From: Esteve Fernandez <esteve@sindominio.net>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: apache2-common: /var/cache/apache2 has wrong permissions
Message-ID: <[🔎] 20040809170313.GA9298@itchy.ratonera>
Reply-To: Esteve Fernandez <esteve@sindominio.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Reportbug-Version: 2.64
User-Agent: Mutt/1.5.6+20040803i
X-BadReturnPath: esteve@itchy.ratonera rewritten as esteve@sindominio.net
  using "Reply-To" header
Delivered-To: submit@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2004_03_25
X-Spam-Level: 

Package: apache2-common
Version: 2.0.50-7
Severity: normal

apache2-common creates /var/cache/apache2 as root:root 755, it
should be www-data:www-data 700

Because:
1) Apache2 runs as www-data and can't access proxy directory since it
is owned by root No data is cached and thus, Apache 2 only acts as a
forward proxy
2) Giving read and execution permissions to others isn't necessary.
Luckily Apache2 creates entries as www-data:www-data 700, so it can't
lead to a security hole.

-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (990, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: i386 (i686)
Kernel: Linux 2.6.7-ck1
Locale: LANG=es_ES, LC_CTYPE=es_ES (ignored: LC_ALL set to es_ES)

Versions of packages apache2-common depends on:
ii  debconf                     1.4.30       Debian configuration management sy
ii  debianutils                 2.8.4        Miscellaneous utilities specific t
ii  libapr0                     2.0.50-7     The Apache Portable Runtime
ii  libc6                       2.3.2.ds1-15 GNU C Library: Shared libraries an
ii  libdb4.2                    4.2.52-16    Berkeley v4.2 Database Libraries [
ii  libexpat1                   1.95.6-8     XML parsing C library - runtime li
ii  libldap2                    2.1.30-3     OpenLDAP libraries
ii  libmagic1                   4.10-3       File type determination library us
ii  libssl0.9.7                 0.9.7d-5     SSL shared libraries
ii  mime-support                3.28-1       MIME files 'mime.types' & 'mailcap
ii  net-tools                   1.60-10      The NET-3 networking toolkit
ii  openssl                     0.9.7d-5     Secure Socket Layer (SSL) binary a
ii  ssl-cert                    1.0-8        Simple debconf wrapper for openssl
ii  zlib1g                      1:1.2.1.1-5  compression library - runtime

-- no debconf information

---------------------------------------
Received: (at 264622-done) by bugs.debian.org; 31 Aug 2004 05:03:43 +0000
>From adconrad@trinitysoftware.com.au Mon Aug 30 22:03:43 2004
Return-path: <adconrad@trinitysoftware.com.au>
Received: from mx1.mail.iig.com.au [203.1.68.15] 
	by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 1C20o2-0006hE-00; Mon, 30 Aug 2004 22:03:43 -0700
Received: by mx1.mail.iig.com.au (Postfix, from userid 10)
	id B70392ABF1; Tue, 31 Aug 2004 15:03:40 +1000 (EST)
Received: from devix (202-14-148-078-soho.dsl.iig.com.au [202.14.148.78])
	by mx1.mail.iig.com.au (Postfix) with ESMTP
	id D51D72A60A; Tue, 31 Aug 2004 15:03:27 +1000 (EST)
From: "Adam Conrad" <adconrad@trinitysoftware.com.au>
To: <263515-done@bugs.debian.org>, <266211-done@bugs.debian.org>,
	<266145-done@bugs.debian.org>, <264645-done@bugs.debian.org>,
	<264622-done@bugs.debian.org>, <267693-done@bugs.debian.org>,
	<266198-done@bugs.debian.org>, <266330-done@bugs.debian.org>,
	<266165-done@bugs.debian.org>, <266736-done@bugs.debian.org>,
	<266279-done@bugs.debian.org>, <266230-done@bugs.debian.org>
Subject: Bug closures
Date: Tue, 31 Aug 2004 15:03:01 +1000
Message-ID: <001c01c48f17$cb93fe30$6400a8c0@int.trinitysoftware.com.au>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.6626
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
Delivered-To: 264622-done@bugs.debian.org
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 
	(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=0.4 required=4.0 tests=BAYES_44,SUSPICIOUS_RECIPS 
	autolearn=no version=2.60-bugs.debian.org_2004_03_25
X-Spam-Level: 
X-CrossAssassin-Score: 2

These bugs were fixed in NMUs by me which are, apparently, no longer
considered NMUs because I'm now part of the apache2 maintenance team.

... Adam

--
backup [n] (bak'up): The duplicate copy of crucial data that no one
                     bothered to make; used only in the abstract.

1024D/C6CEA0C9  C8B2 CB3E 3225 49BB 5ED2  0002 BE3C ED47 C6CE A0C9
 



Reply to: