Hi,

On Sun, Nov 20, 2011 at 06:59:04PM +0000, unknown wrote:
> /usr/lib/cgi-bin/sympa_soap_server.fcgi should not be setuid because
> it is wrapped through sympa_soap_server-wrapper.fcgi to do this.

This is weird because, I've two running installations with sympa 6.1.4
and I fail to see your bug:

# ls -l /usr/lib/cgi-bin/sympa
-rwxr-xr-x 1 root  root  2,0K nov.  19 23:23 sympa_soap_server.fcgi
-rwsr-sr-x 1 sympa sympa 4,3K nov.  19 23:23 sympa_soap_server-wrapper.fcgi
-rwxr-xr-x 1 root  root  598K nov.  19 23:23 wwsympa.fcgi
-rwsr-sr-x 1 sympa sympa 4,3K nov.  19 23:23 wwsympa-wrapper.fcgi

There are only the wrappers which are setuid.


Regards,

M.

-- 
Emmanuel Bouthenot
  mail: kolter@{openics,debian}.org    gpg: 4096R/0x929D42C3
  xmpp: [email protected]          irc: kolter@{freenode,oftc}




-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to