Bug#573524: 'dpkg-reconfigure drupal6' inherits the old user password for a new database

2010-03-12 Thread Luigi Gangitano
severity 573524 normal tags 573524 +moreinfo thanks Hi, would you please explain this issue with more details? dbconfig-common is used in drupal6 to automatically create a database for single domain installation. Is provided for the administrator convenience for simple installation and does

Bug#573524: 'dpkg-reconfigure drupal6' inherits the old user password for a new database

2010-03-12 Thread bht
Hi Luigi, First thank you very much for implementing debian best practice with dbconfig-common for drupal. The bug is not limited to multi site installations. If 'dpkg-reconfigure drupal6' is used to re-configure a single installation for a new, different database with a new, different user,

Bug#573524: 'dpkg-reconfigure drupal6' inherits the old user password for a new database

2010-03-11 Thread bht
Package: drupal6 Version: 6.6-3lenny4 Severity: grave Justification: user security hole Tags: security *** Please type your report below this line *** The workaround is to edit /etc/dbconfig-common/drupal6.conf and set dbc_dbpass='' before executing 'dpkg-reconfigure drupal6', but this results in