Family: Ubuntu Local Security Checks --> Category: infos
USN88-1 : reportbug information disclosure Vulnerability Scan
Vulnerability Scan Summary
reportbug information disclosure
Detailed Explanation for this Vulnerability Test
The remote package "reportbug" is missing a security patch.
Rolf Leggewie discovered two information disclosure bugs in reportbug.
The per-user configuration file ~/.reportbugrc was created
world-readable. If it contained email smarthost passwords, these were
readable by any other user on the computer storing the home directory.
reportbug usually includes the settings from ~/.reportbugrc in
generated bug reports. This included the "smtppasswd" setting (the
password for an SMTP email smarthost) as well. The password is
now hidden from reports.
Upgrade to :
- reportbug-2.62ubuntu1.1 (Ubuntu 4.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.