Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE request: Debian's package "mysql-server" leaks credential information
From: gremlin () gremlin ru
Date: Sat, 8 Jun 2013 15:00:51 +0400

On 08-Jun-2013 12:44:45 +0200, vladz wrote:

The file "/etc/mysql/debian.cnf", which contains plain text
credentials for the "debian-sys-maint" mysql user, is created
in an insecure manner during the package installation phase.
This can lead a non-privileged local user to disclose its content
and use this special account to perform administration tasks.
Could you allocate CVE id for this issue?

That's not a security issue, but a misconfiguration (alas, very common
for Deb*an packages), so at least I doubt that deserves a CVE.

Alexey V. Vissarionov aka Gremlin from Kremlin <gremlin ПРИ gremlin ТЧК ru>
GPG key ID: 0xEF3B1FA8, keyserver: hkp://subkeys.pgp.net
GPG key fingerprint: 8832 FE9F A791 F796 8AC9 6E4E 909D AC45 EF3B 1FA8

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]