|
Message-ID: <20130221181707.GF17951@kludge.henri.nerv.fi> Date: Thu, 21 Feb 2013 20:17:07 +0200 From: Henri Salo <henri@...v.fi> To: oss-security@...ts.openwall.com Cc: Agostino Sarubbo <ago@...too.org>, Kurt Seifried <kseifried@...hat.com> Subject: CVE request: nginx world-readable logdir On Thu, Feb 21, 2013 at 06:50:14PM +0100, Agostino Sarubbo wrote: > Hello, > > I just noticed my nginx logdir and its content are world-readable: > > drwxr-xr-x 2 root root 4096 Jan 10 00:11 . > drwxr-xr-x 16 root root 4096 Feb 21 17:46 .. > -rw-r--r-- 1 root root 69415 Feb 21 17:46 error_log > -rw-r--r-- 1 root root 93017 Feb 18 22:03 localhost.access_log > -rw-r--r-- 1 root root 86227 Feb 18 22:03 localhost.error_log > > What do you think about? > > -- > Agostino Sarubbo / ago -at- gentoo.org > Gentoo Linux Developer Also affects Debian squeeze package. I will report a bug. Can we get a CVE assigned for this issue, thank you. -- Henri Salo
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.