Package: tinyproxy
Version: 1.6.3-2
Severity: normal

Hi,

I noticed the default configuration file grants access to a local
network by default:
| Allow 192.168.1.0/25
Although this is much better than allow access from anywhere this still
can be abused cause harm and confusion in appropriate networks. Please
comment that line out.

-- System Information:
Debian Release: testing/unstable
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.17.13
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=UTF-8)

Versions of packages tinyproxy depends on:
ii  libc6                        2.3.6.ds1-4 GNU C Library: Shared libraries
ii  logrotate                    3.7.1-3     Log rotation utility

tinyproxy recommends no packages.

-- no debconf information

Attachment: signature.asc
Description: Digital signature

Reply via email to