Information Disclosure Vulnerability in reportbug by Debian
CVE-2005-0624

Currently unrated

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
28 February 2005

What is CVE-2005-0624?

The reportbug tool in Debian prior to version 2.62 improperly sets permissions on the .reportbugrc configuration file, making it world-readable. This oversight allows local users to access sensitive information, such as email smarthost passwords stored within the configuration file. Securing this file's permissions is critical to prevent unauthorized access and protect user credentials from being disclosed.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.