LWN.net Logo

initscripts: information exposure

Package(s):initscripts CVE #(s):
Created:October 12, 2007 Updated:October 26, 2007
Description: The initscripts package do not set sufficiently restrictive permissions on the /var/log/btmp file, leading to an information exposure vulnerability in which users' passwords may be revealed to unprivileged users in cases when the passwords have been inadvertently entered as usernames at some login prompts.
Alerts:
Foresight FLEA-2007-0060-1 2007-10-26
rPath rPSA-2007-0214-1 2007-10-11

(Log in to post comments)

initscripts: information exposure

Posted Nov 10, 2007 21:14 UTC (Sat) by kreutzm (guest, #4700) [Link]

Debian and Ubuntu are not affected as the permissions are properly set.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds