On Friday 28 March 2008 17:32:57 Romain Beauxis wrote:
> Package: mini-httpd
> Version: 1.19-7
> Severity: important
>
>       Hi !

Hi,

>
> >From default configuration file, I read:
>
> # We are the web files stored?
> data_dir=/etc/mini-httpd
>
> This is plain wrong and can lead to very serious security issues.
> Please switch to a correct place, usually /var/www...

The place is definitely wrong. But this could not lead to security issues 
because mini-httpd will not start if data_dir does not exist.

with default config:
$ mini-httpd -C /etc/mini-httpd.conf
data_dir chdir: No such file or directory

>
>
>
> Romain

tags 473140 +confirmed
thanks

Cheers,
-- 
 .""`.     Marvin Stark <[EMAIL PROTECTED]>
: :"  :    Homepage: www.der-marv.de
`. `"`
  `-  Debian - when you have better things to do than fix a system

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to