[Secure-testing-team] Bug#711172: phpbb3: creates world writable /var/cache/phpbb3/cache/phpbb3/data_hooks.php
Andreas Beckmann
anbe at debian.org
Wed Jun 5 08:18:46 UTC 2013
Package: phpbb3
Version: 3.0.11-3
Severity: serious
Tags: security
User: debian-qa at lists.debian.org
Usertags: piuparts
Hi,
during a test with piuparts I noticed your package creates a world
writable file:
-rw-rw-rw- 1 root www-data 34 May 29 14:47 /var/cache/phpbb3/cache/phpbb3/data_hooks.php
This was observed on upgrades from sid to experimental.
So far I didn't notice it in any other install or upgrade path.
Andreas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: phpbb3_3.0.11-3.log.gz
Type: application/x-gzip
Size: 11989 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20130605/acced692/attachment.bin>
More information about the Secure-testing-team
mailing list