Bug#406338: lighttpd: /var/log/ligghtpd/*.log is readable by www-data

2014-04-05 Thread Michael Gilbert
Would you mind looking into lighttpd-angel (/usr/sbin/lighttpd-angel),
which was added to lighttpd upstream (and the debian package) almost 7
years ago as a possible fix to your upstream bug report?

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#406338: lighttpd: /var/log/ligghtpd/*.log is readable by www-data

2014-04-05 Thread Olaf van der Spek
Hi team member,

Angel is a 2.0 thing (mostly) AFAIK.

On Sat, Apr 5, 2014 at 8:33 PM, Michael Gilbert mgilb...@debian.org wrote:
 Would you mind looking into lighttpd-angel (/usr/sbin/lighttpd-angel),
 which was added to lighttpd upstream (and the debian package) almost 7
 years ago as a possible fix to your upstream bug report?

 Best wishes,
 Mike



-- 
Olaf


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#406338: lighttpd: /var/log/ligghtpd/*.log is readable by www-data

2010-03-07 Thread Stefan Bühler
Hi,

as lighttpd needs to be able to reopen the logfiles after logrotate, the  www-
data user needs +rw.



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#406338: lighttpd: /var/log/ligghtpd/*.log is readable by www-data

2010-03-07 Thread Olaf van der Spek
2010/3/7 Stefan Bühler light...@stbuehler.de:
 Hi,

 as lighttpd needs to be able to reopen the logfiles after logrotate, the  www-
 data user needs +rw.

See http://redmine.lighttpd.net/issues/show/1271
Use a pipe logger.



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#406338: lighttpd: /var/log/ligghtpd/*.log is readable by www-data

2007-01-10 Thread Olaf van der Spek
Package: lighttpd
Version: 1.4.13-8
Severity: normal

Hi,

/var/log/ligghtpd/*.log is readable and writeable by www-data. User www-data 
should not have this access.



-- System Information:
Debian Release: 4.0
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing')
Architecture: amd64 (x86_64)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-3-amd64
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)

Versions of packages lighttpd depends on:
ii  libattr11:2.4.32-1.1 Extended attribute shared library
ii  libbz2-1.0  1.0.3-6  high-quality block-sorting file co
ii  libc6   2.3.6.ds1-10 GNU C Library: Shared libraries
ii  libldap22.1.30-13.2  OpenLDAP libraries
ii  libpcre36.7-1Perl 5 Compatible Regular Expressi
ii  libssl0.9.8 0.9.8c-4 SSL shared libraries
ii  lsb-base3.1-22   Linux Standard Base 3.1 init scrip
ii  mime-support3.39-1   MIME files 'mime.types'  'mailcap
ii  perl5.8.8-7  Larry Wall's Practical Extraction 
ii  zlib1g  1:1.2.3-13   compression library - runtime

Versions of packages lighttpd recommends:
pn  php4-cgi | php5-cgi   none (no description available)

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]