Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130221181707.GF17951@kludge.henri.nerv.fi>
Date: Thu, 21 Feb 2013 20:17:07 +0200
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Cc: Agostino Sarubbo <ago@...too.org>, Kurt Seifried <kseifried@...hat.com>
Subject: CVE request: nginx world-readable logdir

On Thu, Feb 21, 2013 at 06:50:14PM +0100, Agostino Sarubbo wrote:
> Hello,
> 
> I just noticed my nginx logdir and its content are world-readable:
> 
> drwxr-xr-x  2 root root  4096 Jan 10 00:11 .
> drwxr-xr-x 16 root root  4096 Feb 21 17:46 ..
> -rw-r--r--  1 root root 69415 Feb 21 17:46 error_log
> -rw-r--r--  1 root root 93017 Feb 18 22:03 localhost.access_log
> -rw-r--r--  1 root root 86227 Feb 18 22:03 localhost.error_log
> 
> What do you think about?
> 
> -- 
> Agostino Sarubbo / ago -at- gentoo.org
> Gentoo Linux Developer

Also affects Debian squeeze package. I will report a bug. Can we get a CVE
assigned for this issue, thank you.

--
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.