Public bug reported: Binary package hint: varnish
varnish 2.0.3-2 in ubuntu 9.04 runs varnishlog as root. This is unnecessary and just makes the whole system vulnerable to bugs in varnishlogs parsing of e.g. HTTP header fields. varnish.deb should create a system user and run varnishlog under this user account. ** Affects: varnish (Ubuntu) Importance: Undecided Status: New -- varnishlog should not run as root https://bugs.launchpad.net/bugs/461593 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs