Bug#599712: libapache-authenhook-perl: leaks passwords to the logs

2010-10-13 Thread Ansgar Burchardt
Moritz Muehlenhoff writes: > On Wed, Oct 13, 2010 at 04:30:26PM +0200, Ansgar Burchardt wrote: >> libapache-authenhook-perl logs passwords in Apache's error.log if the >> log level is >= info[1]. I prepared an update for Lenny including the >> same patch used for testing/unstable (already unbloc

Bug#599712: libapache-authenhook-perl: leaks passwords to the logs

2010-10-13 Thread Moritz Muehlenhoff
On Wed, Oct 13, 2010 at 07:34:39PM +0200, Moritz Muehlenhoff wrote: > On Wed, Oct 13, 2010 at 04:30:26PM +0200, Ansgar Burchardt wrote: > > Hi, > > > > libapache-authenhook-perl logs passwords in Apache's error.log if the > > log level is >= info[1]. I prepared an update for Lenny including the >

Bug#599712: libapache-authenhook-perl: leaks passwords to the logs

2010-10-13 Thread Moritz Muehlenhoff
On Wed, Oct 13, 2010 at 04:30:26PM +0200, Ansgar Burchardt wrote: > Hi, > > libapache-authenhook-perl logs passwords in Apache's error.log if the > log level is >= info[1]. I prepared an update for Lenny including the > same patch used for testing/unstable (already unblocked[2] as well). > > Sho

Bug#599712: libapache-authenhook-perl: leaks passwords to the logs

2010-10-13 Thread Ansgar Burchardt
Hi, libapache-authenhook-perl logs passwords in Apache's error.log if the log level is >= info[1]. I prepared an update for Lenny including the same patch used for testing/unstable (already unblocked[2] as well). Should this go through stable-security or does the security team see this as a mino

Bug#599712: libapache-authenhook-perl: leaks passwords to the logs

2010-10-10 Thread Steinar H. Gunderson
Package: libapache-authenhook-perl Version: 2.00-04+pristine-1+b1 Severity: grave Tags: security Justification: user security hole Apache::AuthenHook seemingly logs _all_ usernames and passwords, in clear text, to the vhost's error log: ap_log_rerror(APLOG_MARK, APLOG_INFO, 0, r,