Bug#757438: exposes entire dpkg upgrade log to non-root users

2014-09-11 Thread Michael Vogt
On Fri, Aug 08, 2014 at 03:00:19AM -0400, Joey Hess wrote: > Package: unattended-upgrades > Version: 0.79.5 > Severity: normal > Tags: security Thanks for your bugreport and sorry for my slow reply. > /var/log/unattended-upgrades/ is readable by all, so when this package is > run on a multi-user

Bug#757438: exposes entire dpkg upgrade log to non-root users

2014-08-08 Thread Joey Hess
Package: unattended-upgrades Version: 0.79.5 Severity: normal Tags: security /var/log/unattended-upgrades/ is readable by all, so when this package is run on a multi-user system, non-admin users can trawl the upgrade logs for interesting information. I don't know what they might find.. Which is t