term.log is world readable and shouldn't be
Bug #975199 reported by
James Troup
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apt (Ubuntu) |
Fix Released
|
Undecided
|
Michael Vogt | ||
Oneiric |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Precise |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Quantal |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Raring |
Fix Released
|
Undecided
|
Michael Vogt |
Bug Description
| root@dziban:/etc# ls -l /var/log/
| -rw-r--r-- 1 root adm 87718 Apr 6 10:33 /var/log/
This file includes anything you type into a shell spawned via dpkg's
conffile handling. I don't expect my root shell sessions to be logged
(keystrokes and all) to a world readable file and I imagine I'm not
the only one.
CVE References
Changed in apt (Ubuntu Oneiric): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Quantal): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
information type: | Private Security → Public Security |
Changed in apt (Ubuntu Raring): | |
assignee: | nobody → Michael Vogt (mvo) |
tags: | added: patch |
To post a comment you must log in.
This appears to be a regression in precise. lucid has these files as
600.