Processed: Re: Bug#638955: proftpd-basic: World-readable config files containing password

2011-08-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 638955 normal Bug #638955 [proftpd-basic] proftpd-basic: World-readable config files containing password Severity set to 'normal' from 'grave' > tags 638955 -security Bug #638955 [proftpd-basic] proftpd-basic: World-readable config file

Bug#638955: proftpd-basic: World-readable config files containing password

2011-08-23 Thread Thijs Kinkhorst
severity 638955 normal tags 638955 -security thanks Hi Kim, On Tue, August 23, 2011 12:11, Kim Rostgaard Christensen wrote: > /etc/proftpd/ldap.conf contains passwords and should therefore not be > world readable per default. > > I think the same applies to other vuser backends Thanks for your r

Bug#638955: proftpd-basic: World-readable config files containing password

2011-08-23 Thread Kim Rostgaard Christensen
Package: proftpd-basic Version: 1.3.3a-6squeeze1 Severity: grave Tags: security Justification: user security hole /etc/proftpd/ldap.conf contains passwords and should therefore not be world readable per default. I think the same applies to other vuser backends -- System Information: Debian Rel