[Secure-testing-team] Bug#711172: phpbb3: creates world writable /var/cache/phpbb3/cache/phpbb3/data_hooks.php

Andreas Beckmann anbe at debian.org
Wed Jun 5 08:18:46 UTC 2013


Package: phpbb3
Version: 3.0.11-3
Severity: serious
Tags: security
User: debian-qa at lists.debian.org
Usertags: piuparts

Hi,

during a test with piuparts I noticed your package creates a world
writable file:
  
    -rw-rw-rw- 1 root www-data 34 May 29 14:47 /var/cache/phpbb3/cache/phpbb3/data_hooks.php

This was observed on upgrades from sid to experimental.
So far I didn't notice it in any other install or upgrade path.


Andreas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: phpbb3_3.0.11-3.log.gz
Type: application/x-gzip
Size: 11989 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20130605/acced692/attachment.bin>


More information about the Secure-testing-team mailing list