LWN.net Logo

backup-manager: password disclosure

Package(s):backup-manager CVE #(s):CVE-2007-4656
Created:March 17, 2008 Updated:March 19, 2008
Description:

From the Debian advisory:

Micha Lenk discovered that backup-manager, a command-line backup tool, sends the password as a command line argument when calling a FTP client, which may allow a local attacker to read this password (which provides access to all backed-up files) from the process listing.

Alerts:
Debian DSA-1518-1 2008-03-15

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.