[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [DLA 20-1] munin security update



Hi Vincent,

thanks for your feedback!

On Freitag, 8. August 2014, Vincent Bernat wrote:
> >>    plugins will use /var/lib/munin-node/plugin-state/$uid/$some_file now
> >>    - please report plugins that are still using
> >>    /var/lib/munin/plugin-state/ - as those  might pose a security risk!
> This changes broke the crontab for /etc/munin/plugins/apt_all. Can we
> use the BTS to report that?

Yes, you could, but there is one already:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=720275

This has been finally fixed by git commit b80f5f72 and previously pampered 
over with f356fb30 - I'll probably release a fix for squeeze-lts using 
b80f5f72 later today.


cheers,
	Holger

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: