-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 09 Dec 2022 12:47:07 +0100 Source: fcgiwrap Architecture: source Version: 1.1.0-13 Distribution: unstable Urgency: medium Maintainer: Debian fcgiwrap Maintainers <team+fcgiwrap@tracker.debian.org> Changed-By: Jordi Mallach <jordi@debian.org> Closes: 1023688 Changes: fcgiwrap (1.1.0-13) unstable; urgency=medium . [ Jordi Mallach ] * Tighten permissions and ownership of fcgiwrap socket. This was previously mode 0666, thus writable by any user, which could lead to trivial privilege escalation to www-data. Thanks to Anton Luka Šijanec. (Closes: #1023688) * Bump debhelper compat to v13 and use debhelper-compat to declare it. * Set Rules-Requires-Root to no. * Update copyright years. * Make systemd the main dependency, with spawn-fcgi as the alternative. * Add missing ${misc:Pre-Depends} to handle init-system-helpers requirement. * Update Standards-Version to 4.6.1, with no changes needed. * Add a NEWS.Debian entry pointing out that the socket permission change might break existing setups if they relied on a world-writable socket. * Change all references to /var/run to just /run. . [ Debian Janitor ] * Set upstream metadata fields: Bug-Database, Bug-Submit, Repository-Browse. * Trim trailing whitespace. Checksums-Sha1: 8af9db691e39164e9ad6c4c6f6d2c009e15fcf93 2062 fcgiwrap_1.1.0-13.dsc 872d532db7d3c122b96a1fddfd4d05abd7e583ef 11932 fcgiwrap_1.1.0-13.debian.tar.xz 89bb7dc9847b21160830f5d57e9754c3230a91c7 6747 fcgiwrap_1.1.0-13_amd64.buildinfo Checksums-Sha256: b12a802ea117dc6bf9b49149092626a1d3314a99ea683fd4bfeac3f68b401853 2062 fcgiwrap_1.1.0-13.dsc f1de4b450fcdaae611454948a209fb2c09fbd8cf035cf29f80d4b0ca51292db0 11932 fcgiwrap_1.1.0-13.debian.tar.xz 94e9c1fc5a45a763947942d73dea767f99310c3d6da10fc97755873fde701dec 6747 fcgiwrap_1.1.0-13_amd64.buildinfo Files: 166814bde4efceabb7ad5d36fed4ca58 2062 web optional fcgiwrap_1.1.0-13.dsc 21b2e836f795e8b2ca43830693e5f855 11932 web optional fcgiwrap_1.1.0-13.debian.tar.xz c5eadb67b8409b02451e291917703c30 6747 web optional fcgiwrap_1.1.0-13_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6BdUhsApKYN8KGoWJVAvb8vjywQFAmOTI0MACgkQJVAvb8vj ywRDzA/+KluvHLZVqAOlpaTqqK1MmK0ukdfk/YfMz+SjEBabXGYZB4gBybYDMYzQ g73BYTtOxfZOHKxEaMATMSvdAy+2MiOex/NGg8kpBYNap0GTKKjKymelvFOBn5SR GVEXyU16vl4NcBEZ7iI069hefUh4r3GjdunN8kkd5OH3eo7ig7wt10vK/Klj7jGG RULAtrfsXnVQZWA/cIHW2ZJiQxTAjMYKDoRQ7QzOKxEpnNQ2+VIKgGUx/T+K1qwk 6m4+zx/79A1+KoT06F1lFWuE67KB1znyu71PjooP1Xvj6iF51r48Z+ZBCsKz9w/J a6xfcYCJaYtS8CWdgKNZND1oi1z7Xa6LXKzMlIZv380in3P7kTkTlPZ4PC7VsyFA XaI8Ry+vTW5AQ0hq1x1wjMCI0xJ0btgJn4M3fd7HLVrHBZNDI6CJX08LZ4l5S7Bi rqLanTYlAv/Ym2yt8jsrPqMhhIfU2pVEnCNbyBRCww9Tccyy149snGQ62OzPQlHr T1jOpabIa3fLBifGsODP7ipxdMUAp4+K1Ak5wmalvQMxxLfmkmw5M5AWKzcC/S6w JY6WiLNTL3yz1A/tEn0WejSQExzKJC+EBNmKLhsVe4Mop1BqEmYbzFMW6YtPZ1pv TOchmqSut1ydDyZcDmJni8p3A81bLmwt2AOxFP9yUlc1Zol/J04= =dKWi -----END PGP SIGNATURE-----