Package: phpgroupware
Version: 0.9.16.011-3
Severity: normal

Phpgroupware session cookies seem to get their domain set to the domain
instead of the fqdn...

On a server like phpgroupware.mydomain.com, the cookies domain will be
'.mydomain.com'.

I thinks this is not a generic setup which would match most installation
where several phpgroupware servers could be installed on the same
network and be isolated session-wide.

Correct me if I'm wrong as I'm no expert in cookie specification.

Best regards,


-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.18-4-686 (SMP w/1 CPU core)
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages phpgroupware depends on:
ii  apache2-mpm-prefork [httpd] 2.2.3-4      Traditional model for Apache HTTPD
ii  debconf [debconf-2.0]       1.5.13       Debian configuration management sy
ii  mysql-client-5.0 [mysql-cli 5.0.38-1     mysql database client binaries
ii  php4                        6:4.4.4-9    server-side, HTML-embedded scripti
ii  php4-cgi                    6:4.4.4-9    server-side, HTML-embedded scripti
ii  php4-mysql                  6:4.4.4-9    MySQL module for php4
ii  php5-imap                   5.2.0-10     IMAP module for php5
ii  phpgroupware-admin          0.9.16.011-3 phpGroupWare administration module
ii  phpgroupware-phpgwapi       0.9.16.011-3 library of common phpGroupWare fun
ii  phpgroupware-preferences    0.9.16.011-3 phpGroupWare preferences managemen
ii  phpgroupware-setup          0.9.16.011-3 phpGroupWare setup III module
ii  wwwconfig-common            0.0.48       Debian web auto configuration

Versions of packages phpgroupware recommends:
ii  php4-ldap                     6:4.4.4-9  LDAP module for php4

-- debconf information:
  phpgroupware/debug:
* phpgroupware/db/type: MySQL
  phpgroupware/db/user/password/mismatch:
  phpgroupware/db/setup/skip: false
* phpgroupware/db/user/name: phpgroupware
  phpgroupware/db/setup/abort:
  phpgroupware/configuration/overwrite: false
* phpgroupware/webserver: apache2
  phpgroupware/header/password/mismatch:
* phpgroupware/db/host: localhost
* phpgroupware/db/admin/name: root
  phpgroupware/configuration/note:
  phpgroupware/configuration/password/mismatch:
* phpgroupware/postrm: true
* phpgroupware/db/name: phpgroupware


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to