Bug#1080079: apache2: Upgrade from Debian 11 to 12 seems to have enabled serve-cgi-bin.conf (security risk)

Ralf Bergs <[email protected]>
Newsgroups gmane.linux.debian.devel.apache
Message-ID <335921b7-efa5-4a13-a194-0cd6ef19e55c__44669.4817672082$1725032011$gmane$org@bergs.biz>
On 2024-08-30 17:03, Ondřej Surý wrote:
> I think that’s the problem - the script doesn’t only delete or create the symlinks, but it records whether admin or maintainer did the change, and honors the choice. Otherwise the package has no way to know whether the link is missing because of the upgrade or by mistake, and recreates the links.
Ok, I checked the script again, and I can now indeed confirm it's 
registering the states in /var/lib/apache2/conf/

I now recreated the links manually, and then used the script to remove 
them. And indeed there's now new entries in 
/var/lib/apache2/conf/disabled_by_admin/

So this seems to be a layer 8 problem. Please close this ticket. And 
thank you for your help.
smime.p7s (application/pkcs7-signature, 4.6 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.