Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130608104445.GA3565@devzero.fr>
Date: Sat, 8 Jun 2013 12:44:45 +0200
From: vladz <vladz@...zero.fr>
To: oss-security@...ts.openwall.com
Subject: CVE request: Debian's package "mysql-server" leaks credential
 information

Hi,

The file "/etc/mysql/debian.cnf", which contains plain text credentials
for the "debian-sys-maint" mysql user, is created in an insecure manner
during the package installation phase.  This can lead a non-privileged
local user to disclose its content and use this special account to
perform administration tasks.

  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=711600

Could you allocate CVE id for this issue?

Thank you,
vladz.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.