Bug#448850: closed by Luis Rodrigo Gallardo Cruz <[EMAIL PROTECTED]> (Re: Bug#448850: CVE-2007-5751 insecure file permissions of feedlist.ompl backup file)

2007-11-01 Thread Nico Golde
Hi, > From: Luis Rodrigo Gallardo Cruz <[EMAIL PROTECTED]> > Version: 1.4.6-1 > > On Thu, Nov 01, 2007 at 01:30:45PM +0100, Nico Golde wrote: > > CVE-2007-5751[0]: > > | Liferea before 1.4.6 uses weak permissions (0644) for the > > | feedlist.opml backup file, which allows local users to > > | o

Bug#448850: CVE-2007-5751 insecure file permissions of feedlist.ompl backup file

2007-11-01 Thread Nico Golde
Hi Lars, * Lars Lindner <[EMAIL PROTECTED]> [2007-11-01 16:43]: > On 11/1/07, Luis Rodrigo Gallardo Cruz <[EMAIL PROTECTED]> wrote: > > On Thu, Nov 01, 2007 at 01:30:45PM +0100, Nico Golde wrote: > > > CVE-2007-5751[0]: > > > | Liferea before 1.4.6 uses weak permissions (0644) for the > > > | feedl

Bug#448850: CVE-2007-5751 insecure file permissions of feedlist.ompl backup file

2007-11-01 Thread Lars Lindner
On 11/1/07, Luis Rodrigo Gallardo Cruz <[EMAIL PROTECTED]> wrote: > On Thu, Nov 01, 2007 at 01:30:45PM +0100, Nico Golde wrote: > > CVE-2007-5751[0]: > > | Liferea before 1.4.6 uses weak permissions (0644) for the > > | feedlist.opml backup file, which allows local users to > > | obtain credentials

Bug#448850: CVE-2007-5751 insecure file permissions of feedlist.ompl backup file

2007-11-01 Thread Luis Rodrigo Gallardo Cruz
On Thu, Nov 01, 2007 at 01:30:45PM +0100, Nico Golde wrote: > CVE-2007-5751[0]: > | Liferea before 1.4.6 uses weak permissions (0644) for the > | feedlist.opml backup file, which allows local users to > | obtain credentials. It appears that the problem is not present in 1.0.*, as those versions

Bug#448850: CVE-2007-5751 insecure file permissions of feedlist.ompl backup file

2007-11-01 Thread Nico Golde
Package: liferea Version: 1.0.27-1 Severity: important Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for liferea. CVE-2007-5751[0]: | Liferea before 1.4.6 uses weak permissions (0644) for the | feedlist.opml backup file, which allows local users