security issue: config.pyc vulnerability
will guaraldi <[email protected]>
| Newsgroups | gmane.comp.web.pyblosxom.user |
|---|---|
| Message-ID | <[email protected]> |
I posted a security issue notification on the web-site today:
http://pyblosxom.sourceforge.net/blog/security/security.07252005.html
To quote:
----
Zack sends this email:
Hello,
I discovered this vulnerability while playing with pyblosxom,
which uses python files to store configuration information. The
way it is packaged by Debian, the global config file /etc/
pyblosxom/config.py is created with 640 permissions, owned by the
root user and the www-data group, of which apache httpd is a
member. When the config file is imported by pyblosxom, a
config.pyc is created with 644 permissions. If, for example, an
XMLRPC password is specified in that file, it will be readable by
any user.
We're looking into how we can alleviate this issue. We've contacted the Debian
maintainer and will work with him to fix the issue in Debian. I haven't looked
into whether this affects other distributions or not.
In the meantime if you're running PyBlosxom in such a way, make sure the
permissions to your config.pyc file are appropriate.
----
Any comments, ideas, thoughts, and such--let us know!
/will
-------------------------------------------------------
SF.Net email is sponsored by: Discover Easy Linux Migration Strategies
from IBM. Find simple to follow Roadmaps, straightforward articles,
informative Webcasts and more! Get everything you need to get up to
speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click