Bug#832460: World readable .rediscli_history

2016-07-25 Thread kpcyrd
> > Another bug report by @denisvm, this time on the linenoise library: > > https://github.com/antirez/linenoise/issues/121 > > Indeed this looks like it might affect some other packages in Debian: > > https://codesearch.debian.net/search?q=int+linenoiseHistorySave&perpkg=1 > > Can you check th

Bug#832460: World readable .rediscli_history

2016-07-25 Thread Chris Lamb
> Another bug report by @denisvm, this time on the linenoise library: > https://github.com/antirez/linenoise/issues/121 Indeed this looks like it might affect some other packages in Debian: https://codesearch.debian.net/search?q=int+linenoiseHistorySave&perpkg=1 Can you check these? I'm about t

Bug#832460: World readable .rediscli_history

2016-07-25 Thread kpcyrd
> > I've contacted upstream on 2016-05-30 without any reaction at all and > > discovered this bug was first reported 3 years ago, still unfixed. > > @RedisLabs keeps referring to their paid support on twitter. > > Boo. Is there an upstream bug# for this or was this reported privately? My report:

Bug#832460: World readable .rediscli_history

2016-07-25 Thread Chris Lamb
> I've contacted upstream on 2016-05-30 without any reaction at all and > discovered this bug was first reported 3 years ago, still unfixed. > @RedisLabs keeps referring to their paid support on twitter. Boo. Is there an upstream bug# for this or was this reported privately? Regards, --

Bug#832460: World readable .rediscli_history

2016-07-25 Thread kpcyrd
Package: redis-tools Version: 2.8.17-1+deb8u3 Severity: grave Tags: security redis-cli stores its history in ~/.rediscli_history, this file is created with permissions 0644. Home folders are world readable as well in debian, so any user can access other users redis history, including AUTH commands