Package: postfixadmin Version: 3.0.2-1 Severity: normal On my system /usr/share/postfixadmin/templates_c had mode 0777, I don't know how it got that.
In the package it has mode 0755 with ownership root:root. I think that the correct mode might be 0775 or 0770 with ownership root:www-data. Apache must be able to write to this directory for Postfixadmin in a fairly standard configuration to work without giving a HTTP error 500. But a world writable directory without the tag bit is obviously a problem (I don't know if that was a package issue or a local config issue). -- System Information: Debian Release: 9.0 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'testing'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.9.0-1-amd64 (SMP w/2 CPU cores) Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages postfixadmin depends on: ii apache2 [httpd] 2.4.25-3 ii dbconfig-common 2.0.8 ii debconf 1.5.60 ii libapache2-mod-php 1:7.0+49 ii libapache2-mod-php7.0 [libapache2-mod-php] 7.0.15-1 ii php-imap 1:7.0+49 ii php-mbstring 1:7.0+49 ii php-mysql 1:7.0+49 ii php7.0-imap [php-imap] 7.0.15-1 ii php7.0-mbstring [php-mbstring] 7.0.15-1 ii php7.0-mysql [php-mysqlnd] 7.0.15-1 ii postgresql-client 9.6+179 ii postgresql-client-9.6 [postgresql-client] 9.6.2-1 ii wwwconfig-common 0.3.0 Versions of packages postfixadmin recommends: ii dovecot-core 1:2.2.27-2 pn mariadb-server <none> ii php7.0-cli [php-cli] 7.0.15-1 ii postfix-mysql 3.1.4-4 pn virtual-mysql-server | postgresql | sqlite <none> pn zendframework <none> postfixadmin suggests no packages. -- Configuration Files: /etc/postfixadmin/config.inc.php changed [not included] -- debconf information excluded