Not logged in
Log in now
Create an account
Subscribe to LWN
Recent Features
Book review: Open Advice
Linux support for ARM big.LITTLE
LWN.net Weekly Edition for February 9, 2012
XBMC 11 "Eden"
LWN.net Weekly Edition for February 2, 2012
From the CVE:
The FTP backend for Duplicity sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.
duplicity: password disclosure
Posted Feb 14, 2008 20:21 UTC (Thu) by kreutzm (subscriber, #4700) [Link]
Debian Sarge and Etch are not vulnerable.
Copyright © 2012, Eklektix, Inc. Comments and public postings are copyrighted by their creators. Linux is a registered trademark of Linus Torvalds