[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#5233: cgi-scripts 1.0.1-1 breaks permissions



Package: cgi-scripts
Version: 1.0.1-1


the package ruins the permissions of the following directories:

drwxrws--- root/www-data     0 1996-09-25 10:32 usr/lib/
drwxrws--- root/www-data     0 1996-09-25 10:32 usr/lib/httpd/
drwxrws--- root/www-data     0 1996-09-25 10:32 usr/lib/httpd/cgi-bin/

fortunately, /usr and /usr/lib already exist, so their permissions don't
get changed.

files in cgi-bin are installed as:

-rwxr-x--- root/www-data  6216 1996-09-25 10:32 usr/lib/httpd/cgi-bin/animate
-rwxr-x--- root/www-data   373 1996-09-25 10:32 usr/lib/httpd/cgi-bin/archie
-rwxr-x--- root/www-data   413 1996-09-25 10:32 usr/lib/httpd/cgi-bin/calendar
-rwxr-x--- root/www-data  4648 1996-09-25 10:32 usr/lib/httpd/cgi-bin/count
-rwxr-x--- root/www-data   151 1996-09-25 10:32 usr/lib/httpd/cgi-bin/date
-rwxr-x--- root/www-data   384 1996-09-25 10:32 usr/lib/httpd/cgi-bin/finger
-rwxr-x--- root/www-data   172 1996-09-25 10:32 usr/lib/httpd/cgi-bin/fortune
-rwxr-x--- root/www-data  7144 1996-09-25 10:32 usr/lib/httpd/cgi-bin/imagemap
-rwxr-x--- root/www-data 13132 1996-09-25 10:32 usr/lib/httpd/cgi-bin/mailto.pl
-rwxr-x--- root/www-data  4844 1996-09-25 10:32 usr/lib/httpd/cgi-bin/post-query
-rwxr-x--- root/www-data  4592 1996-09-25 10:32 usr/lib/httpd/cgi-bin/query
-rwxr-x--- root/www-data  4572 1996-09-25 10:32 usr/lib/httpd/cgi-bin/random
-rwxr-x--- root/www-data   165 1996-09-25 10:32 usr/lib/httpd/cgi-bin/uptime
-rwxr-x--- root/www-data  2675 1996-09-25 10:32 usr/lib/httpd/cgi-bin/wais.pl

actually, not setting o+x might be a good thing - requires the sysadmin
to deliberately enable the execute bit on the scripts s/he wants to run.
Regardless of that, they should all be world readable.


also, the cgiscriptsconfig(8) command included in the package defines
it's install command as:

    cmd="install -m 750"

should be:
    cmd="install -m 754"
or
    cmd="install -m 755"

apache 1.1.1-5 has a similar problem.  stay tuned for the next bug report.

Craig


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-devel-REQUEST@lists.debian.org . Trouble? e-mail to Bruce@Pixar.com


Reply to: