Bug#1080079: apache2: Upgrade from Debian 11 to 12 seems to have enabled serve-cgi-bin.conf (security risk)
Ralf Bergs <[email protected]>
| Newsgroups | gmane.linux.debian.devel.apache |
|---|---|
| Message-ID | <a7468242-109f-41a4-a3cb-592675b8257b__33107.9367127799$1725030566$gmane$org@bergs.biz> |
On 2024-08-30 12:58, Ondřej Surý wrote: > your report is missing the information on **how** did you disabled serve-cgi-bin.conf? Ah, sorry. I manually deleted the link from conf-available/ to conf-enabled/. I later had some doubts whether I had asked for problems by doing so, I checked the a2disconf script, and if I'm not mistaken it basically does the same thing. In any case I didn't find evidence that the script "registered" this action somewhere, which would be the precondition for not "force-enabling" it later...
smime.p7s
(application/pkcs7-signature, 4.6 KB) - not displayed