Bug#824878: targetcli: Sensitive information exposed in configuration and backup files

2016-06-13 Thread Ritesh Raj Sarraf
Hello Christoph, Thank you for the bug report. The same is fixed in the new (-3) upload, pending inclusion into archives soon. Thanks. On Fri, 2016-05-20 at 18:57 +0200, Christoph Scheurer wrote: > Package: targetcli > Version: 1:3.0~pre4.1~ga55d018-2 > Severity: normal > > Dear Maintainer, >

Bug#824878: targetcli: Sensitive information exposed in configuration and backup files

2016-05-20 Thread Christoph Scheurer
Package: targetcli Version: 1:3.0~pre4.1~ga55d018-2 Severity: normal Dear Maintainer, the configuration file /etc/target/scsi_target.lio as well as backups in /var/target/ are created with permissions 644 (also depending on root's umask, of course). These files contain the clear text password(s)