COMMAND
httpdsd
SYSTEMS AFFECTED
Trustix
PROBLEM
Oystein Viggen posted following. Due to a typo in the rpm spec
file for apache-ssl, /usr/sbin/httpsd on a Trustix system will be
installed with mode 756 instead of 755, making a binary file that
will be run by root world writable. It should not be necessary to
explain why this is an extremely bad thing.
SOLUTION
This bug is easily removed by doing "chmod 755 /usr/sbin/httpsd".
A new rpm package has been made availible on our ftp site:
i586 RPM: ftp://ftp.trustix.com/pub/Trustix/updates/1.1/RPMS/apache-ssl-1.3.12_1.39-7tr.i586.rpm
SRPM: ftp://ftp.trustix.com/pub/Trustix/updates/1.1/SRPMS/apache-ssl-1.3.12_1.39-7tr.src.rpm