Package: apache2-common Severity: important
Hi. As I know, many people use debian as base of sahred hosting. And in most cases, user data are stored in /home/*/public_html/ and it's subdirs. For now, suexec2 does not work outside /var/www. Yes, maybe on non-shared system single /var/www dir works well, but if I'd like to run cgi scripts from /home/... I have to use single user for all scripts to run. It is not secure in case when I have untrusted users. Please, add to package ability to select different suexec binaries with different docroot, maybe it could be choosen by alternatives. For now, I must get sources for apache2, fix debian/rules and rebuild package - it disallow me to use automatic update tools and force to install developer tools and -dev packages that are not needed on production server. I think, I'm not only man who have such problem. Similar reports: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=340946 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=266835 -- System Information: Debian Release: testing/unstable APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.15-1-686 Locale: LANG=be_BY.UTF-8, LC_CTYPE=be_BY.UTF-8 (charmap=UTF-8) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]