[pkg-horde] Bug#514528: Bug#514528: Kronolith reminders cronjob should run as www-data user

Ola Lundqvist opal at debian.org
Sun Feb 8 22:46:12 UTC 2009


Hi

Fully agree. Will be corrected when lenny is out of the door.

Best regards,

// Ola

On Sun, Feb 08, 2009 at 02:06:14PM +0100, Mathieu Parent wrote:
> Package: kronolith2
> Version: 2.2-1
> Severity: normal
> Tags: patch
> 
> The cronjob currently run as root. Appart from security considerations,
> temp files created while executing the sript are only readable/writable
> by root.
> 
> This breaks Kolab cache handling.
> 
> Patch:
> --- /etc/cron.d/kronolith2.old	2009-02-08 12:36:21.000000000 +0000
> +++ /etc/cron.d/kronolith2	2009-02-08 12:36:44.000000000 +0000
> @@ -1,4 +1,4 @@
>  #
>  # Regular cron jobs for the kronolith2 package
>  #
> -* * * * * root test -x /usr/bin/php && /usr/bin/php -q
> /usr/share/horde3/kronolith/scripts/reminders.php > /dev/null 2>&1
> +* * * * * www-data test -x /usr/bin/php && /usr/bin/php -q
> /usr/share/horde3/kronolith/scripts/reminders.php > /dev/null 2>&1
> 
> 
> Upstream doc: http://wiki.horde.org/KronolithReminders
> 
> -- System Information:
> Debian Release: 5.0
>   APT prefers testing
>   APT policy: (900, 'testing'), (300, 'unstable')
> Architecture: i386 (i686)
> 
> Kernel: Linux 2.6.26-1-xen-686 (SMP w/1 CPU core)
> Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
> Shell: /bin/sh linked to /bin/dash
> 
> 
> 
> _______________________________________________
> pkg-horde-hackers mailing list
> pkg-horde-hackers at lists.alioth.debian.org
> http://lists.alioth.debian.org/mailman/listinfo/pkg-horde-hackers
> 

-- 
 --------------------- Ola Lundqvist ---------------------------
/  opal at debian.org                     Annebergsslingan 37      \
|  ola at inguza.com                      654 65 KARLSTAD          |
|  http://inguza.com/                  +46 (0)70-332 1551       |
\  gpg/f.p.: 7090 A92B 18FE 7994 0C36  4FE4 18A1 B1CF 0FE5 3DD9 /
 ---------------------------------------------------------------





More information about the pkg-horde-hackers mailing list