Bug#499191: Possible security issues

2009-02-01 Thread Alexander Prinsier
Alexander Prinsier wrote: > I have a patch prepared. Attached is what I got so far, and seems to be > working fine. (It's the modified .dpatch file, not a patch to a dpatch). And this is the file... #! /bin/sh /usr/share/dpatch/dpatch-run ## 202_suexec-custom.dpatch by Stefan Fritsch ## ## All li

Bug#499191: Possible security issues

2009-02-01 Thread Alexander Prinsier
I have a patch prepared. Attached is what I got so far, and seems to be working fine. (It's the modified .dpatch file, not a patch to a dpatch). So now a third line in /etc/apache2/suexec/www-data is supported, being a cgi_docroot. Scripts inside this cgi_docroot, and owned by root are allowed to

[bts-link] source package apache2

2009-02-01 Thread bts-link-upstream
# # bts-link upstream status pull for source package apache2 # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html # user bts-link-upstr...@lists.alioth.debian.org # remote status report for #363964 # * http://issues.apache.org/bugzilla/show_bug.cgi?id=39369 # * remote statu