[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1080079: apache2: Upgrade from Debian 11 to 12 seems to have enabled serve-cgi-bin.conf (security risk)



On 2024-08-30 17:03, Ondřej Surý wrote:
I think that’s the problem - the script doesn’t only delete or create the symlinks, but it records whether admin or maintainer did the change, and honors the choice. Otherwise the package has no way to know whether the link is missing because of the upgrade or by mistake, and recreates the links.
Ok, I checked the script again, and I can now indeed confirm it's registering the states in /var/lib/apache2/conf/

I now recreated the links manually, and then used the script to remove them. And indeed there's now new entries in /var/lib/apache2/conf/disabled_by_admin/

So this seems to be a layer 8 problem. Please close this ticket. And thank you for your help.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


Reply to: