[Logcheck-devel] linitian check of current version
maks attems
debian at sternwelten.at
Thu May 6 20:43:36 UTC 2004
logcheck-database and logtail are clean, but
W: logcheck: possibly-insecure-handling-of-tmp-files-in-maintainer-script postinst:56
the offending line in debian/logcheck.postinstall:
chown -R logcheck /var/tmp/logcheck* &> /dev/null || true
todd do we really need this line?
did you want to catch a running logcheck, while upgrading?
the next logcheck tmp dir should have anyway correct permissions,
do we need to care about these leftovers?
E: logcheck: depends-on-essential-package-without-using-version bash
probably not too bad to add a sensitive number there,
does anyone have preference?
a++ maks
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20040506/43e79a4f/attachment.pgp
More information about the Logcheck-devel
mailing list