LWN.net Logo

ntlmaps: wrong permissions

Package(s):ntlmaps CVE #(s):CAN-2005-2962
Created:September 30, 2005 Updated:October 5, 2005
Description: Drew Parsons noticed that the post-installation script of ntlmaps, an NTLM authorization proxy server, changes the permissions of the configuration file to be world-readable. It contains the user name and password of the Windows NT system that ntlmaps connects to and, hence, leaks them to local users.
Alerts:
Debian DSA-830-1 2005-09-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds