Package: iodine
Version: 0.4.0-1
Severity: normal

Because the password is stored in /etc/default/iodine please make sure
to install this file with 600 access mode.

Also, please modify iodine/iodined to XXX out the password passed to it
via the command line. This is not a perfect but certainly substantial
security improvement because it makes the password not show up in most
"ps xawww" calls.

memset(argv[n], 'X', strlen(argv[n])) shold do the job in n is the
argument number with the password.

Thanks,
        Lennart

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.18-4-686 (SMP w/1 CPU core)
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages iodine depends on:
ii  adduser                       3.102      Add and remove users and groups
ii  debconf [debconf-2.0]         1.5.13     Debian configuration management sy
ii  libc6                         2.5-9+b1   GNU C Library: Shared libraries
ii  makedev                       2.3.1-83   creates device files in /dev
ii  zlib1g                        1:1.2.3-13 compression library - runtime

iodine recommends no packages.

-- debconf information excluded


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to