| Summary: | net-misc/vpnc - world-readable credentials | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Jakub Moc (RETIRED) <jakub> |
| Component: | Default Configs | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | CC: | fauli, hanno |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | B4 [noglsa] Falco | ||
| Package list: | Runtime testing required: | --- | |
| Bug Depends on: | |||
| Bug Blocks: | 158271 | ||
|
Description
Jakub Moc (RETIRED)
2007-02-14 09:51:45 UTC
Indeed hanno has sent a patch upstream, we wait for integration. Now 0.4.0 is in and I'd like to soon remove all older versions. Security, do you think this is worth an advisory? It's imho no real security flaw, just bad defaults. Archs, please mark stable vpnc-0.4.0 so we can get rid of the svn-snapshot ebuilds. x86 stable ppc64 stable (In reply to comment #3) > Security, do you think this is worth an advisory? It's imho no real security > flaw, just bad defaults. > probably no ppc stable amd64 stable undecided... tend to vote no though the account used for my uni's vpn is the same as for mail etc, so it might contain pretty sensitive information yet another no (In reply to comment #11) > yet another no > i agree |