Fw: [Ipcop-svn] SF.net SVN: ipcop:[6232] Fix permissions of redirect-background.jpg
"Gilles Espinasse" <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.devel |
|---|---|
| Message-ID | <275e01ccd3c6$649f2b40$f9b5a8c0@pii350> |
----- Original Message ----- From: <[email protected]> To: <[email protected]> Sent: Sunday, January 15, 2012 9:28 PM Subject: [Ipcop-svn] SF.net SVN: ipcop:[6232] ipcop/trunk > Revision: 6232 > http://ipcop.svn.sourceforge.net/ipcop/?rev=6232&view=rev > Author: dotzball > Date: 2012-01-15 20:28:33 +0000 (Sun, 15 Jan 2012) > Log Message: > ----------- > Fix permissions of redirect-background.jpg > > Modified Paths: > -------------- > ipcop/trunk/lfs/ipcop-gui > ipcop/trunk/updates/2.0.3/setup > > Modified: ipcop/trunk/lfs/ipcop-gui > =================================================================== > --- ipcop/trunk/lfs/ipcop-gui 2012-01-15 16:55:44 UTC (rev 6231) > +++ ipcop/trunk/lfs/ipcop-gui 2012-01-15 20:28:33 UTC (rev 6232) > @@ -78,6 +78,9 @@ > chown nobody:nobody /home/httpd/html/backup > chmod 744 /home/httpd/html/backup > > + # redirect background image needs nobody:nobody permissions as it can be written by webui > + chown nobody.nobody /home/httpd/html/images/redirect-background.jpg > + I don't like that much but haven't yet look why this is needed and if there is a better way to do that. With security in view, that mean that nobody user could control a jpg image and that we would need now to be carefull of jpg vulnerabilities. Previously images were out of control of the user and no image could affect the security of the machine when displayed. Gilles ------------------------------------------------------------------------------ RSA(R) Conference 2012 Mar 27 - Feb 2 Save $400 by Jan. 27 Register now! http://p.sf.net/sfu/rsa-sfdev2dev2