[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 3074-2] php5 regression update



Le mercredi 19 novembre 2014 à 15:12, Sébastien NOBILI a écrit :
> Le mercredi 19 novembre 2014 à 14:57, David MENTRE a écrit :
> > Le 19/11/2014 11:49, Yves-Alexis Perez a écrit :
> > >so people are advised to keep kernel
> > >symlink protection (sysctl fs.protected_symlinks=1) enabled as it is by
> > >default on Wheezy
> > 
> > This setting is not set on my Wheezy machine.
> > 
> > How can I set it permanently (i.e. across reboots).
> 
> You can create a file (with « .conf » extension) in directory /etc/sysctl.d
> where you define the value. You can have a look at /etc/sysctl.conf for syntax.

Sorry, this variable should be set to 1 by default on Wheezy. So you should seek
for a definition to 0 on your system and disable it (comment out the line or
delete the file):

    grep -r protected_symlinks /etc/sysctl.conf /etc/sysctl.d/*

Seb


Reply to: