Bug#319943: pyblosxom: config.pyc vulnerability

2006-01-30 Thread will guaraldi
On Mon, 30 Jan 2006, Tollef Fog Heen wrote: * Norbert Tretkowski | > I would think the latter isn't particularly great since it prevents | > more than one user to use PyBlosxom on a given machine. | | Agreed. I'll think about it. It's the site-wide configuration file. It's trivial to set up a

Bug#319943: pyblosxom: config.pyc vulnerability

2006-01-30 Thread Tollef Fog Heen
* Norbert Tretkowski | No... /etc/pyblosxom/ is owned by root, pyblosxom.cgi is started from | apache(2), which runs as user www-data. So, no way to create config.py | in /etc/pyblosxom. apache isn't a syscall just yet. ;-) | > Or are they supposed to configure config.py in /etc/pyblosxom? | |

Bug#319943: pyblosxom: config.pyc vulnerability

2006-01-29 Thread Norbert Tretkowski
* will guaraldi wrote: > On Sun, 29 Jan 2006, Norbert Tretkowski wrote: > > On Debian systems, there's no config.pyc created, so I'm a bit > > puzzled about this bugreport. > > Well, there's no config.pyc file created at install time. But if > someone sets up their blog and points their blog at >

Bug#319943: pyblosxom: config.pyc vulnerability

2006-01-29 Thread will guaraldi
On Sun, 29 Jan 2006, Norbert Tretkowski wrote: * will guaraldi wrote: I discovered this vulnerability while playing with pyblosxom, which uses python files to store configuration information. The way it is packaged by Debian, the global config file /etc/pyblosxom/config.py is created with 640 p

Bug#319943: pyblosxom: config.pyc vulnerability

2006-01-29 Thread Norbert Tretkowski
* will guaraldi wrote: >> I discovered this vulnerability while playing with pyblosxom, which >> uses python files to store configuration information. The way it is >> packaged by Debian, the global config file /etc/pyblosxom/config.py >> is created with 640 permissions, owned by the root user and

Bug#319943: pyblosxom: config.pyc vulnerability

2005-07-25 Thread will guaraldi
Package: pyblosxom Severity: normal I got an email from Ted who got an email from David who got an email from Zack which reads as follows: > Hello, > > I discovered this vulnerability while playing with pyblosxom, which uses > python files to store configuration information. The way it is packag