Package: apt-cacher
Version: 1.6.8
Severity: normal

The default installation of /etc/apt-cacher/apt-cacher.conf contains
line:

    allowed_hosts=*

Which:

    # Localhost (127.0.0.1) is always allowed. Other addresses must be matched
    # by allowed_hosts and not by denied_hosts to be permitted to use the cache.
    # Setting allowed_hosts to "*" means "allow all".

Please consider security and allow only localhost or some 192.168.*.*
value in default installation.

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable'), (1, 
'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages apt-cacher depends on:
ii  bzip2                         1.0.5-1    high-quality block-sorting file co
ii  ed                            0.7-3      The classic unix line editor
ii  libdigest-sha1-perl           2.11-2+b1  NIST SHA-1 message digest algorith
ii  libfreezethaw-perl            0.45-1     converting Perl structures to stri
ii  libwww-curl-perl              4.05-1     Perl bindings to libcurl
ii  libwww-perl                   5.820-1    WWW client/server library for Perl
ii  perl                          5.10.0-19  Larry Wall's Practical Extraction 

Versions of packages apt-cacher recommends:
ii  libberkeleydb-perl            0.38-1     use Berkeley DB 4 databases from P

Versions of packages apt-cacher suggests:
ii  libio-socket-inet6-perl       2.54-1     Object interface for AF_INET6 doma

-- no debconf information



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to