XSP server listens on 0.0.0.0 by default, autostarted on package install
Bug #1861166 reported by
Adam Piggott
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
mono-tools (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
I installed mono-complete 5.18.0.240+dfsg-3 on Ubuntu 19.10 as a user, rather than a coder (to use plugins for the password manager KeePass). I then noticed that monodoc-http 4.2-3 seems to have configured a web server (XSP4) to autostart and listen on port 8084 on 0.0.0.0. This might be considered a security risk and perhaps the server autostarting might not be considered ideal.
To post a comment you must log in.