Package: sbox-dtc
Version: 1.11.2-1
Severity: grave

The file /usr/lib/cgi-bin/sbox should have the SUID bit set, as this is
the way sbox works, and also, it should be owned by the root user to
allow chroot in the vhost directory.

The patch would be simple. Just adding this in the postinst:

chmod u=+rwS /usr/lib/cgi-bin/sbox
chown root.root /usr/lib/cgi-bin/sbox

Thomas Goirand (zigo)

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.32-5-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to