Package: mini-httpd
Version: 1.19-7
Severity: important

        Hi !

>From default configuration file, I read:
# We are the web files stored?
data_dir=/etc/mini-httpd

This is plain wrong and can lead to very serious security issues.
Please switch to a correct place, usually /var/www...



Romain
-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.24-rc7-mactel (SMP w/2 CPU cores; PREEMPT)
Locale: LANG=fr_FR, LC_CTYPE=fr_FR (charmap=ISO-8859-1)
Shell: /bin/sh linked to /bin/bash

Versions of packages mini-httpd depends on:
ii  libc6                         2.7-9      GNU C Library: Shared libraries
ii  libssl0.9.8                   0.9.8g-7   SSL shared libraries

mini-httpd recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to