Package: drupal6 Version: 6.6-3lenny4 Severity: grave Justification: user security hole Tags: security
*** Please type your report below this line *** The workaround is to edit /etc/dbconfig-common/drupal6.conf and set dbc_dbpass='' before executing 'dpkg-reconfigure drupal6', but this results in an ugly prompt after execution. -- System Information: Debian Release: 5.0.4 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel: Linux 2.6.26-2-686 (SMP w/1 CPU core) Locale: LANG=en_NZ.UTF-8, LC_CTYPE=en_NZ.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages drupal6 depends on: ii apache2 2.2.9-10+lenny6 Apache HTTP Server metapackage ii apache2-mpm-prefor 2.2.9-10+lenny6 Apache HTTP Server - traditional n ii curl 7.18.2-8lenny3 Get a file from an HTTP, HTTPS or ii dbconfig-common 1.8.39 common framework for packaging dat ii debconf [debconf-2 1.5.24 Debian configuration management sy ii exim4 4.69-9 metapackage to ease Exim MTA (v4) reportbug did not let me save the report even though i told it that I have no MTA configured. So this goes out from my PC mail program. Sorry. drupal6/password-confirm: (password omitted) drupal6/pgsql/app-pass: (password omitted) drupal6/mysql/admin-pass: (password omitted) drupal6/mysql/app-pass: (password omitted) drupal6/pgsql/admin-pass: (password omitted) drupal6/app-password-confirm: (password omitted) drupal6/pgsql/manualconf: * drupal6/mysql/method: unix socket drupal6/pgsql/authmethod-user: drupal6/purge: false drupal6/remove-error: abort drupal6/dbconfig-upgrade: true drupal6/pgsql/admin-user: postgres drupal6/install-error: abort drupal6/dbconfig-remove: * drupal6/db/dbname: test3 drupal6/pgsql/changeconf: false drupal6/internal/skip-preseed: false drupal6/pgsql/method: unix socket drupal6/missing-db-package-error: abort drupal6/upgrade-error: abort drupal6/remote/host: drupal6/db/basepath: drupal6/passwords-do-not-match: drupal6/internal/reconfiguring: false drupal6/pgsql/no-empty-passwords: * drupal6/db/app-user: test3 * drupal6/database-type: mysql drupal6/upgrade-backup: true drupal6/dbconfig-reinstall: false * drupal6/mysql/admin-user: root drupal6/pgsql/authmethod-admin: ident drupal6/remote/newhost: * drupal6/dbconfig-install: true drupal6/remote/port: -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org