Package: tomcat6 Version: 6.0.28-9+squeeze1 Severity: important tomcat6.postinst uses adduser --no-create-home and then the deb file puts files in /usr/share/tomcat6/ ($TOMCAT6_USER's home) are owned by root. Lots of application write to this folder.
-- System Information: Debian Release: 6.0 APT prefers squeeze-updates APT policy: (500, 'squeeze-updates'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.32-5-amd64 (SMP w/4 CPU cores) Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages tomcat6 depends on: ii adduser 3.112+nmu2 add and remove users and groups ii debconf [debconf-2.0] 1.5.36.1 Debian configuration management sy ii tomcat6-common 6.0.28-9+squeeze1 Servlet and JSP engine -- common f ii ucf 3.0025+nmu1 Update Configuration File: preserv Versions of packages tomcat6 recommends: ii authbind 1.2.0 Allows non-root programs to bind() Versions of packages tomcat6 suggests: pn tomcat-native <none> (no description available) ii tomcat6-admin 6.0.28-9+squeeze1 Servlet and JSP engine -- admin we pn tomcat6-docs <none> (no description available) pn tomcat6-examples <none> (no description available) pn tomcat6-user <none> (no description available) -- Configuration Files: /etc/tomcat6/tomcat-users.xml [Errno 13] Permission denied: u'/etc/tomcat6/tomcat-users.xml' -- debconf information: tomcat6/javaopts: -Djava.awt.headless=true -Xmx128m -XX:+UseConcMarkSweepGC tomcat6/groupname: tomcat6 tomcat6/username: tomcat6 __ This is the maintainer address of Debian's Java team <http://lists.alioth.debian.org/mailman/listinfo/pkg-java-maintainers>. Please use debian-j...@lists.debian.org for discussions and questions.