[pkg-horde] Bug#726187: Bug#726187: Provice empty conf.php and conf.bak.php (writeable for ww-data)

Mathieu Parent math.parent at gmail.com
Tue Oct 22 19:25:02 UTC 2013


Control: tag -1 + wontfix

2013/10/13 Mike Gabriel <mike.gabriel at das-netzwerkteam.de>:
> Package: php-horde
> Version: 5.1.4+debian0-1
>
> To allow editing the Horde configuration administratively, two files need to
> be present in /etc/horde/horde.
>
>   conf.php
>   conf.bak.php
>
> Both files have to be writable by user www-data.

I don't want this because this is a security hole IMO.

But, I welcome a patch to:
- create those files owned by root
- improve the documentation (README.Debian)

Regards
-- 
Mathieu



More information about the pkg-horde-hackers mailing list