Your message dated Sat, 23 Feb 2008 11:47:03 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#462864: fixed in papercut 0.9.13-5
has caused the Debian Bug report #462864,
regarding papercut: should not run with root permissions
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
462864: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=462864
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: papercut
Severity: serious
Tags: security
It's a bad idea to run any kind of daemon, which is accessible from the
outside, as root. While papercut needs to start as root to bind to the
nntp port, I can't see any reason why it should not drop it's privileges
to handle requests.
--
Bernd Zeimetz
<[EMAIL PROTECTED]> <http://bzed.de/>
--- End Message ---
--- Begin Message ---
Source: papercut
Source-Version: 0.9.13-5
We believe that the bug you reported is fixed in the latest version of
papercut, which is due to be installed in the Debian FTP archive:
papercut_0.9.13-5.diff.gz
to pool/main/p/papercut/papercut_0.9.13-5.diff.gz
papercut_0.9.13-5.dsc
to pool/main/p/papercut/papercut_0.9.13-5.dsc
papercut_0.9.13-5_all.deb
to pool/main/p/papercut/papercut_0.9.13-5_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Juan Angulo Moreno <[EMAIL PROTECTED]> (supplier of updated papercut package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 20 Feb 2008 03:29:33 -0430
Source: papercut
Binary: papercut
Architecture: source all
Version: 0.9.13-5
Distribution: unstable
Urgency: low
Maintainer: Debian QA Group <[EMAIL PROTECTED]>
Changed-By: Juan Angulo Moreno <[EMAIL PROTECTED]>
Description:
papercut - simple and extensible NNTP server
Closes: 445407 462864
Changes:
papercut (0.9.13-5) unstable; urgency=low
.
* QA Group upload.
* Added debian/papercut.postinst with user/group creation. (Closes: #462864)
* Fixed debian/papercut.postrm with delete user support.
* Fixed debian/papercut.init (with user daemon support).
* Added debian/pyDaemon.py library.
* Fixed papercut script with pyDaemon.py.
* Fixed .pid file (Its uses the default directory /var/run/papercut).
* Fixed debian/README.Debian: little error typo. (Closes: #445407)
* Update Debhelper 6.
* Update Standards Version to 3.7.3.
Files:
db14a3d66f96519a408dfd8e26b0b138 718 news optional papercut_0.9.13-5.dsc
a79fa574e14ca7d41ec11abdc3ad552b 18144 news optional papercut_0.9.13-5.diff.gz
dabf490a46ea78f90f3d3aa331992dd7 42660 news optional papercut_0.9.13-5_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHwAWWgY5NIXPNpFURAldWAKDcIz1R6aarplaFiIvLeS0Z5VlbtACgpq+t
lNL9svZK0hB27mBFCKlHI8g=
=GDFU
-----END PGP SIGNATURE-----
--- End Message ---