security issue: config.pyc vulnerability

will guaraldi <[email protected]>
Newsgroups gmane.comp.web.pyblosxom.user
Message-ID <[email protected]>
I posted a security issue notification on the web-site today:

    http://pyblosxom.sourceforge.net/blog/security/security.07252005.html

To quote:
----

Zack sends this email:

    Hello,

    I discovered this vulnerability while playing with pyblosxom,
    which uses python files to store configuration information. The
    way it is packaged by Debian, the global config file /etc/
    pyblosxom/config.py is created with 640 permissions, owned by the
    root user and the www-data group, of which apache httpd is a
    member. When the config file is imported by pyblosxom, a
    config.pyc is created with 644 permissions. If, for example, an
    XMLRPC password is specified in that file, it will be readable by
    any user.

We're looking into how we can alleviate this issue. We've contacted the Debian 
maintainer and will work with him to fix the issue in Debian. I haven't looked 
into whether this affects other distributions or not.

In the meantime if you're running PyBlosxom in such a way, make sure the 
permissions to your config.pyc file are appropriate.

----

Any comments, ideas, thoughts, and such--let us know!

/will


-------------------------------------------------------
SF.Net email is sponsored by: Discover Easy Linux Migration Strategies
from IBM. Find simple to follow Roadmaps, straightforward articles,
informative Webcasts and more! Get everything you need to get up to
speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.