Bug#1004080: asterisk: Configuration files owned by asterisk user

2022-01-24 Thread Jonas Smedegaard
Quoting Johannes Drexl (2022-01-24 16:44:19) > Am Donnerstag, dem 20.01.2022 um 16:17 +0100 schrieb Jonas Smedegaard: > > An obvious next step might be to try make the suggested change and > > see if it still seems to work the same. Did you try that already, > > Drexl? If not, can I ask you to

Bug#1004080: asterisk: Configuration files owned by asterisk user

2022-01-24 Thread Johannes Drexl
Am Donnerstag, dem 20.01.2022 um 16:17 +0100 schrieb Jonas Smedegaard: > An obvious next step might be to try make the suggested change and > see > if it still seems to work the same. Did you try that already, Drexl? > If not, can I ask you to try it? Hi Jonas, will do internally when I'm

Bug#1004080: asterisk: Configuration files owned by asterisk user

2022-01-20 Thread Jonas Smedegaard
Hi Drexl, Quoting Drexl Johannes (2022-01-20 15:41:40) > I'm not entirely sure this poses a threat, but as I understand general > security directives state not to give the executing user of a service > write access to its config files and binaries. Yet after installing > the package the whole

Bug#1004080: asterisk: Configuration files owned by asterisk user

2022-01-20 Thread Drexl Johannes
Package: asterisk Version: 1:16.16.1~dfsg-1+deb11u1 Severity: normal Tags: security X-Debbugs-Cc: johannes.dr...@nfon.com, Debian Security Team I'm not entirely sure this poses a threat, but as I understand general security directives state not to give the executing user of a service write