Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-12 Thread Francesco P. Lovergine
On Sat, Dec 11, 2010 at 03:14:17AM +0100, Florian Zumbiehl wrote: > > Well, yeah, there is also a vulnerability due to this maintainer > script itself--though I mostly intended to point out the vulnerability > in logrotate which could be fixed in such a way that logrotate > itself could create new

Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, > On Fri, Dec 10, 2010 at 03:10:19AM +0100, Florian Zumbiehl wrote: > > Package: aolserver4 > > Version: 4.5.0-16.1 > > Severity: grave > > Justification: privilege escalation vulnerability > > Tags: security > > --- > > c

Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Francesco P. Lovergine
On Fri, Dec 10, 2010 at 03:10:19AM +0100, Florian Zumbiehl wrote: > Package: aolserver4 > Version: 4.5.0-16.1 > Severity: grave > Justification: privilege escalation vulnerability > Tags: security > --- > chown -R www-data:www-