[Logcheck-devel] linitian check of current version

maks attems debian at sternwelten.at
Thu May 6 20:43:36 UTC 2004


logcheck-database and logtail are clean, but

W: logcheck: possibly-insecure-handling-of-tmp-files-in-maintainer-script postinst:56

the offending line in debian/logcheck.postinstall:
       chown -R logcheck /var/tmp/logcheck* &> /dev/null || true

todd do we really need this line?
did you want to catch a running logcheck, while upgrading?
the next logcheck tmp dir should have anyway correct permissions,
do we need to care about these leftovers?
        

E: logcheck: depends-on-essential-package-without-using-version bash

probably not too bad to add a sensitive number there,
does anyone have preference?


a++ maks

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20040506/43e79a4f/attachment.pgp 


More information about the Logcheck-devel mailing list