Accepted fcgiwrap 1.1.0-13 (source) into unstable
- To: debian-devel-changes@lists.debian.org
- Subject: Accepted fcgiwrap 1.1.0-13 (source) into unstable
- From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
- Date: Fri, 09 Dec 2022 12:19:45 +0000
- Debian: DAK
- Debian-architecture: source
- Debian-archive-action: accept
- Debian-changes: fcgiwrap_1.1.0-13_source.changes
- Debian-source: fcgiwrap
- Debian-suite: unstable
- Debian-version: 1.1.0-13
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id: Content-Transfer-Encoding:Content-Type:Subject:MIME-Version:To:Reply-To:From: Cc:Content-ID:Content-Description:In-Reply-To:References; bh=aAuw+E/NGIpfrYIzsBodRng4zDQOPC/cb+pMTlzGAbI=; b=Rq4sHl8pfRuMlAuXAfaneHF5my UbpEEdoFMkXxDN9Dfb26LZRzrskgtY3/BCci7RC1uQ+i3OV9GjpPlFDKjWSOH4EI2IQzqTDasTRbm +plTTN1wogpgQwwA3RjVPmLRSq2WQRtcU/JyPwLtEBIskwE1Fr6YShHbK/aXIJx/XG2UW9xf0xppF TaEofbPzkD3zAisUL3p7aaMYxyCMwGMp86AXmGxbzN5bewYyVnnEzkraPxrLjugbeT+n4pZemiuBj OA87EHbYKM8mDXhZzsOxLN/BTKsiT4gqTazaiMbkUTheihPRULd/l4QSye1JcuSwnZQn9hjYNVdl7 LvBMZpEg==;
- Mail-followup-to: debian-devel@lists.debian.org
- Message-id: <E1p3cLx-00BHfR-Gs@fasolo.debian.org>
- Reply-to: debian-devel@lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 09 Dec 2022 12:47:07 +0100
Source: fcgiwrap
Architecture: source
Version: 1.1.0-13
Distribution: unstable
Urgency: medium
Maintainer: Debian fcgiwrap Maintainers <team+fcgiwrap@tracker.debian.org>
Changed-By: Jordi Mallach <jordi@debian.org>
Closes: 1023688
Changes:
fcgiwrap (1.1.0-13) unstable; urgency=medium
.
[ Jordi Mallach ]
* Tighten permissions and ownership of fcgiwrap socket.
This was previously mode 0666, thus writable by any user,
which could lead to trivial privilege escalation to www-data.
Thanks to Anton Luka Šijanec. (Closes: #1023688)
* Bump debhelper compat to v13 and use debhelper-compat to declare it.
* Set Rules-Requires-Root to no.
* Update copyright years.
* Make systemd the main dependency, with spawn-fcgi as the alternative.
* Add missing ${misc:Pre-Depends} to handle init-system-helpers requirement.
* Update Standards-Version to 4.6.1, with no changes needed.
* Add a NEWS.Debian entry pointing out that the socket permission change
might break existing setups if they relied on a world-writable socket.
* Change all references to /var/run to just /run.
.
[ Debian Janitor ]
* Set upstream metadata fields: Bug-Database, Bug-Submit, Repository-Browse.
* Trim trailing whitespace.
Checksums-Sha1:
8af9db691e39164e9ad6c4c6f6d2c009e15fcf93 2062 fcgiwrap_1.1.0-13.dsc
872d532db7d3c122b96a1fddfd4d05abd7e583ef 11932 fcgiwrap_1.1.0-13.debian.tar.xz
89bb7dc9847b21160830f5d57e9754c3230a91c7 6747 fcgiwrap_1.1.0-13_amd64.buildinfo
Checksums-Sha256:
b12a802ea117dc6bf9b49149092626a1d3314a99ea683fd4bfeac3f68b401853 2062 fcgiwrap_1.1.0-13.dsc
f1de4b450fcdaae611454948a209fb2c09fbd8cf035cf29f80d4b0ca51292db0 11932 fcgiwrap_1.1.0-13.debian.tar.xz
94e9c1fc5a45a763947942d73dea767f99310c3d6da10fc97755873fde701dec 6747 fcgiwrap_1.1.0-13_amd64.buildinfo
Files:
166814bde4efceabb7ad5d36fed4ca58 2062 web optional fcgiwrap_1.1.0-13.dsc
21b2e836f795e8b2ca43830693e5f855 11932 web optional fcgiwrap_1.1.0-13.debian.tar.xz
c5eadb67b8409b02451e291917703c30 6747 web optional fcgiwrap_1.1.0-13_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE6BdUhsApKYN8KGoWJVAvb8vjywQFAmOTI0MACgkQJVAvb8vj
ywRDzA/+KluvHLZVqAOlpaTqqK1MmK0ukdfk/YfMz+SjEBabXGYZB4gBybYDMYzQ
g73BYTtOxfZOHKxEaMATMSvdAy+2MiOex/NGg8kpBYNap0GTKKjKymelvFOBn5SR
GVEXyU16vl4NcBEZ7iI069hefUh4r3GjdunN8kkd5OH3eo7ig7wt10vK/Klj7jGG
RULAtrfsXnVQZWA/cIHW2ZJiQxTAjMYKDoRQ7QzOKxEpnNQ2+VIKgGUx/T+K1qwk
6m4+zx/79A1+KoT06F1lFWuE67KB1znyu71PjooP1Xvj6iF51r48Z+ZBCsKz9w/J
a6xfcYCJaYtS8CWdgKNZND1oi1z7Xa6LXKzMlIZv380in3P7kTkTlPZ4PC7VsyFA
XaI8Ry+vTW5AQ0hq1x1wjMCI0xJ0btgJn4M3fd7HLVrHBZNDI6CJX08LZ4l5S7Bi
rqLanTYlAv/Ym2yt8jsrPqMhhIfU2pVEnCNbyBRCww9Tccyy149snGQ62OzPQlHr
T1jOpabIa3fLBifGsODP7ipxdMUAp4+K1Ak5wmalvQMxxLfmkmw5M5AWKzcC/S6w
JY6WiLNTL3yz1A/tEn0WejSQExzKJC+EBNmKLhsVe4Mop1BqEmYbzFMW6YtPZ1pv
TOchmqSut1ydDyZcDmJni8p3A81bLmwt2AOxFP9yUlc1Zol/J04=
=dKWi
-----END PGP SIGNATURE-----