[Pkg-sympa-devel] Bug#639911: Wrong setuid on sympa_soap_server.fcgi

Emmanuel Bouthenot kolter at openics.org
Sun Nov 20 20:04:47 UTC 2011


Hi,

On Sun, Nov 20, 2011 at 06:59:04PM +0000, unknown wrote:
> /usr/lib/cgi-bin/sympa_soap_server.fcgi should not be setuid because
> it is wrapped through sympa_soap_server-wrapper.fcgi to do this.

This is weird because, I've two running installations with sympa 6.1.4
and I fail to see your bug:

# ls -l /usr/lib/cgi-bin/sympa
-rwxr-xr-x 1 root  root  2,0K nov.  19 23:23 sympa_soap_server.fcgi
-rwsr-sr-x 1 sympa sympa 4,3K nov.  19 23:23 sympa_soap_server-wrapper.fcgi
-rwxr-xr-x 1 root  root  598K nov.  19 23:23 wwsympa.fcgi
-rwsr-sr-x 1 sympa sympa 4,3K nov.  19 23:23 wwsympa-wrapper.fcgi

There are only the wrappers which are setuid.


Regards,

M.

-- 
Emmanuel Bouthenot
  mail: kolter@{openics,debian}.org    gpg: 4096R/0x929D42C3
  xmpp: kolter at im.openics.org          irc: kolter@{freenode,oftc}






More information about the Pkg-sympa-devel mailing list