Package: src:dtc
Version: 0.32.5-1
Severity: grave
Tags: upstream security
Justification: user security hole

dtc passes passwords to htpasswd using command line arguments. To quote
htpasswd(1):

  This option should be used with extreme care, since the password is
  clearly visible on the command line.

Regards,
Ansgar



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to