Bug#482085: freeradius leaves /var/log/freeradius world readable with world readable files in it

2008-05-20 Thread Stephen Gran
This one time, at band camp, Harhalakis Stefanos said: > By default freeradius leaves /var/log/freeradius with permissions 755. > Enabling sqltrace will result in a world-readable sqltrace in this, > possibly containing cleartext passwords. Agg! Sorry, my brain is clearly not engaged. I read the

Bug#482085: freeradius leaves /var/log/freeradius world readable with world readable files in it

2008-05-20 Thread Stephen Gran
severity 482085 normal tags 482085 -security thanks This one time, at band camp, Harhalakis Stefanos said: > Justification: user security hole That's perhaps an exageration. > By default freeradius leaves /var/log/freeradius with permissions 755. > Enabling sqltrace will result in a world-readab

Bug#482085: freeradius leaves /var/log/freeradius world readable with world readable files in it

2008-05-20 Thread Harhalakis Stefanos
Package: freeradius Version: 1.1.7-1 Severity: grave Tags: security Justification: user security hole By default freeradius leaves /var/log/freeradius with permissions 755. Enabling sqltrace will result in a world-readable sqltrace in this, possibly containing cleartext passwords. Been there, don