|
|
| |
|
| |
initscripts: information exposure
| Package(s): | initscripts |
CVE #(s): | |
| Created: | October 12, 2007 |
Updated: | October 26, 2007 |
| Description: |
The initscripts package do not set sufficiently restrictive permissions on
the /var/log/btmp file, leading to an information exposure vulnerability in
which users' passwords may be revealed to unprivileged users in cases when
the passwords have been inadvertently entered as usernames at some login
prompts. |
| Alerts: |
|
( Log in to post comments)
|
|
|