Bug#659296: surf: world-readable cookie jar

2012-02-10 Thread Jakub Wilk
* Jakub Wilk , 2012-02-10, 00:05: $ ls -ld ~/.surf/{,cookies.txt} drwxr-xr-x 2 user users 4096 Feb 9 22:59 /home/user/.surf/ -rw-r--r-- 1 user users 406 Feb 9 22:59 /home/user/.surf/cookies.txt CVE-2012-0842 was assigned to this bug. -- Jakub Wilk -- To UNSUBSCRIBE, email to debian-bugs-

Bug#659296: surf: world-readable cookie jar

2012-02-09 Thread Jakub Wilk
Package: surf Version: 0.4.1-4.1 Severity: grave Tags: security Justification: user security hole $ ls -ld ~/.surf/{,cookies.txt} drwxr-xr-x 2 user users 4096 Feb 9 22:59 /home/user/.surf/ -rw-r--r-- 1 user users 406 Feb 9 22:59 /home/user/.surf/cookies.txt This allows local users to steal co