Please do not reply directly to this email. All additional comments should be made in the comments box of this bug.
https://bugzilla.redhat.com/show_bug.cgi?id=441378
manuel wolfshant wolfy@nobugconsulting.ro changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED AssignedTo|nobody@fedoraproject.org |wolfy@nobugconsulting.ro
--- Comment #9 from manuel wolfshant wolfy@nobugconsulting.ro 2008-08-30 19:23:42 EDT --- What's the reasoning behind using %attr(2775, root, apache) %{_localstatedir}/lib/%{name}/images and not %attr(755, apache, root) %{_localstatedir}/lib/%{name}/images ?
This will allow apache to write in the images directory (as required by the cgi) and avoid using any suid.
Look for a full review soon.