Package: phpgroupware Version: 0.9.16.011-3 Severity: normal Phpgroupware session cookies seem to get their domain set to the domain instead of the fqdn...
On a server like phpgroupware.mydomain.com, the cookies domain will be '.mydomain.com'. I thinks this is not a generic setup which would match most installation where several phpgroupware servers could be installed on the same network and be isolated session-wide. Correct me if I'm wrong as I'm no expert in cookie specification. Best regards, -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Kernel: Linux 2.6.18-4-686 (SMP w/1 CPU core) Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15) Shell: /bin/sh linked to /bin/bash Versions of packages phpgroupware depends on: ii apache2-mpm-prefork [httpd] 2.2.3-4 Traditional model for Apache HTTPD ii debconf [debconf-2.0] 1.5.13 Debian configuration management sy ii mysql-client-5.0 [mysql-cli 5.0.38-1 mysql database client binaries ii php4 6:4.4.4-9 server-side, HTML-embedded scripti ii php4-cgi 6:4.4.4-9 server-side, HTML-embedded scripti ii php4-mysql 6:4.4.4-9 MySQL module for php4 ii php5-imap 5.2.0-10 IMAP module for php5 ii phpgroupware-admin 0.9.16.011-3 phpGroupWare administration module ii phpgroupware-phpgwapi 0.9.16.011-3 library of common phpGroupWare fun ii phpgroupware-preferences 0.9.16.011-3 phpGroupWare preferences managemen ii phpgroupware-setup 0.9.16.011-3 phpGroupWare setup III module ii wwwconfig-common 0.0.48 Debian web auto configuration Versions of packages phpgroupware recommends: ii php4-ldap 6:4.4.4-9 LDAP module for php4 -- debconf information: phpgroupware/debug: * phpgroupware/db/type: MySQL phpgroupware/db/user/password/mismatch: phpgroupware/db/setup/skip: false * phpgroupware/db/user/name: phpgroupware phpgroupware/db/setup/abort: phpgroupware/configuration/overwrite: false * phpgroupware/webserver: apache2 phpgroupware/header/password/mismatch: * phpgroupware/db/host: localhost * phpgroupware/db/admin/name: root phpgroupware/configuration/note: phpgroupware/configuration/password/mismatch: * phpgroupware/postrm: true * phpgroupware/db/name: phpgroupware -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]