Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2010-01-06 Thread Teodor MICU
[please don't use -quiet as I didn't received the responses though I want to contribute were I can] 2010/1/4 Patrick Schoenfeld : >> I've noticed in the past that cacti RE-adds the symbolic link >> conf.d/cacti.conf >> on every upgrade even if the source file was *manually* removed by the >> sys

Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2010-01-07 Thread Patrick Schoenfeld
On Wed, Jan 06, 2010 at 05:44:28PM +0200, Teodor MICU wrote: > [please don't use -quiet as I didn't received the responses though I > want to contribute were I can] > > 2010/1/4 Patrick Schoenfeld : > >> I've noticed in the past that cacti RE-adds the symbolic link > >> conf.d/cacti.conf > >> on

Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2010-01-07 Thread Patrick Schoenfeld
Tags 561339 patch thanks Hi, attached is a patch that changes behaviour of postinst so, that symlink is only created on a fresh installation. Feel free to use it, if you wish. Best Regards, Patrick diff -u -Nur cacti-0.8.7e.bak/debian/cacti.postinst cacti-0.8.7e/debian/cacti.postinst --- cacti-

Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2010-01-08 Thread Teodor MICU
severity 561477 wishlist retitle 561477 please improve the debconf question about web server configuration thanks On Thu, Jan 7, 2010 at 11:17 AM, Patrick Schoenfeld wrote: > On Wed, Jan 06, 2010 at 05:44:28PM +0200, Teodor MICU wrote: >> Ok, now I see that this is a way of disabling that symlin

Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2009-12-17 Thread Teodor
Package: cacti Version: 0.8.7e-1.1 Severity: grave Tags: security Justification: user security hole I've noticed in the past that cacti RE-adds the symbolic link conf.d/cacti.conf on every upgrade even if the source file was *manually* removed by the sysadmin. This is done to restrict the access t

Bug#561477: [Secure-testing-team] Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2009-12-17 Thread Michael Gilbert
On Thu, 17 Dec 2009 16:13:36 +0200, Teodor wrote: > Package: cacti > Version: 0.8.7e-1.1 > Severity: grave > Tags: security > Justification: user security hole > > I've noticed in the past that cacti RE-adds the symbolic link > conf.d/cacti.conf > on every upgrade even if the source file was *man

Bug#561477: [Secure-testing-team] Bug#561477: [security] must not RE-add /etc/apache2/conf.d/cacti.conf link on upgrade

2009-12-17 Thread Teodor MICU
On Thu, Dec 17, 2009 at 5:51 PM, Michael Gilbert wrote: > On Thu, 17 Dec 2009 16:13:36 +0200, Teodor wrote: >> As it can be seen postinstall already has a check for the existence of the >> config >> file /etc/cacti/apache.conf. Please add the same check for creating the >> symlink. > > this may