Menu

#3987 apache update remove libapache2-mod-php5

1.560
open
5
2011-09-10
2011-09-10
Anonymous
No

At the Apache update from apache2 2.2.9-10+lenny10 to apache2 2.2.9-10+lenny11 with Webmin
Webmin removes the libapache2-mod and did not reinstall it. This is a huge problem cause everyone can then download the php.files for example config.php and can see the source code wich can include mysql passwords.

Log started: 2011-09-10 09:36:30
(Reading database ... 70907 files and directories currently installed.)
Preparing to replace apache2 2.2.9-10+lenny10 (using .../apache2_2.2.9-10+lenny11_all.deb) ...
Unpacking replacement apache2 ...
(Reading database ... 70905 files and directories currently installed.)
Removing libapache2-mod-php5 ...
Module php5 disabled.

Discussion

  • Jamie Cameron

    Jamie Cameron - 2011-09-11

    This is an oddity with the Debian Apache packages - for some reason, they un-install libapache2-mod-php5. It isn't Virtualmin that is doing this, but actually the Debian package dependency system. This fix is to just manually re-install libapache2-mod-php5..

     
  • Nobody/Anonymous

    If you are shure it's not webmin then print a note on your package update site like "WARNING ATM APACHE DELETES THE libapache2-mod-php AFTER THAT EVERYONE CAN DOWNLOAD YOUR PHP SOURCECODE"
    or try if you can make a workaround for example check if libapache2-mod-php is installed and reinstall it automatically I think nobody wants to delete an installed module during an update

     

Log in to post a comment.