Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-2214

Опубликовано: 11 июл. 2005
Источник: debian

Описание

apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apt-setupunfixedpackage

Примечания

  • That's by design. We want to provide non-root users access to the source code,

  • thus it needs to be world-readable. Also, the password can't be too sensitive

  • as it'll be sent non-encrypted over the wire.

Связанные уязвимости

ubuntu
около 20 лет назад

apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

nvd
около 20 лет назад

apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

github
больше 3 лет назад

apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.