Hi,

The directories /var/log/cobbler, /var/log/cobbler/tasks and 
/var/log/cobbler/kicklog are owned by the apache/wwwrun user. Is this really 
needed?
I'm asking because of a potential security risk in that:
http://article.gmane.org/gmane.comp.security.oss.general/4404

For me it looks like only the cobblerd is writing those and so root:root would 
be sufficient.


-- 
ciao, Uwe Gansert

Uwe Gansert
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nürnberg)
Business: http://www.suse.de/~ug
_______________________________________________
cobbler-devel mailing list
cobbler-devel@lists.fedorahosted.org
https://fedorahosted.org/mailman/listinfo/cobbler-devel

Reply via email to