mailing list archives
Re: CVE request: Debian's package "mysql-server" leaks credential information
From: gremlin () gremlin ru
Date: Sat, 8 Jun 2013 15:00:51 +0400
On 08-Jun-2013 12:44:45 +0200, vladz wrote:
The file "/etc/mysql/debian.cnf", which contains plain text
credentials for the "debian-sys-maint" mysql user, is created
in an insecure manner during the package installation phase.
This can lead a non-privileged local user to disclose its content
and use this special account to perform administration tasks.
Could you allocate CVE id for this issue?
That's not a security issue, but a misconfiguration (alas, very common
for Deb*an packages), so at least I doubt that deserves a CVE.
Alexey V. Vissarionov aka Gremlin from Kremlin <gremlin ПРИ gremlin ТЧК ru>
GPG key ID: 0xEF3B1FA8, keyserver: hkp://subkeys.pgp.net
GPG key fingerprint: 8832 FE9F A791 F796 8AC9 6E4E 909D AC45 EF3B 1FA8
Re: CVE request: Debian's package "mysql-server" leaks credential information Daniel Kahn Gillmor (Jun 08)