diff -Nru mumble-1.2.2/debian/changelog mumble-1.2.2/debian/changelog --- mumble-1.2.2/debian/changelog 2010-07-12 15:36:23.000000000 +0200 +++ mumble-1.2.2/debian/changelog 2011-01-20 12:23:05.000000000 +0100 @@ -1,3 +1,11 @@ +mumble (1.2.2-4ubuntu0.1) maverick-security; urgency=low + + * SECURITY UPDATE: /etc/mumble-server.ini is world readable. (LP: #704674) + - debian/mumble-server.postinst: Set permissions of mumble-server.ini to + 0640 and the owner to root:mumble-server. + + -- Felix Geyer Thu, 20 Jan 2011 12:22:57 +0100 + mumble (1.2.2-4) unstable; urgency=high * Fix failure with SQLite with very long 'like' matches. diff -Nru mumble-1.2.2/debian/control mumble-1.2.2/debian/control --- mumble-1.2.2/debian/control 2010-07-08 18:04:36.000000000 +0200 +++ mumble-1.2.2/debian/control 2011-01-19 11:08:43.000000000 +0100 @@ -2,7 +2,8 @@ Section: sound Priority: optional Homepage: http://mumble.sourceforge.net/ -Maintainer: Debian VoIP Team +Maintainer: Ubuntu Developers +XSBC-Original-Maintainer: Debian VoIP Team Uploaders: Patrick Matthäi , Thorvald Natvig Build-Depends: debhelper (>= 7.0.8), po-debconf, libboost-dev (>= 1.36.0), libboost-python-dev (>= 1.36.0), diff -Nru mumble-1.2.2/debian/mumble-server.postinst mumble-1.2.2/debian/mumble-server.postinst --- mumble-1.2.2/debian/mumble-server.postinst 2010-01-11 17:01:23.000000000 +0100 +++ mumble-1.2.2/debian/mumble-server.postinst 2011-01-20 12:19:19.000000000 +0100 @@ -26,6 +26,10 @@ chmod 0750 /var/lib/mumble-server chown mumble-server:adm /var/log/mumble-server chown mumble-server:mumble-server /var/lib/mumble-server + if [ -f /etc/mumble-server.ini ]; then + chmod 0640 /etc/mumble-server.ini + chown root:mumble-server /etc/mumble-server.ini + fi # Workaround for when this was in .dirs [ -d /var/run/mumble-server ] && chown mumble-server:adm /var/run/mumble-server