Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-12 Thread Francesco P. Lovergine
On Sat, Dec 11, 2010 at 03:14:17AM +0100, Florian Zumbiehl wrote: Well, yeah, there is also a vulnerability due to this maintainer script itself--though I mostly intended to point out the vulnerability in logrotate which could be fixed in such a way that logrotate itself could create new log

Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Francesco P. Lovergine
On Fri, Dec 10, 2010 at 03:10:19AM +0100, Florian Zumbiehl wrote: Package: aolserver4 Version: 4.5.0-16.1 Severity: grave Justification: privilege escalation vulnerability Tags: security --- chown -R www-data:www-data

Bug#606554: aolserver4: affected by privilege escalation vulnerability in logrotate

2010-12-10 Thread Florian Zumbiehl
Hi, On Fri, Dec 10, 2010 at 03:10:19AM +0100, Florian Zumbiehl wrote: Package: aolserver4 Version: 4.5.0-16.1 Severity: grave Justification: privilege escalation vulnerability Tags: security --- chown -R