This one time, at band camp, Harhalakis Stefanos said:
> By default freeradius leaves /var/log/freeradius with permissions 755.
> Enabling sqltrace will result in a world-readable sqltrace in this,
> possibly containing cleartext passwords.
Agg!
Sorry, my brain is clearly not engaged. I read the
severity 482085 normal
tags 482085 -security
thanks
This one time, at band camp, Harhalakis Stefanos said:
> Justification: user security hole
That's perhaps an exageration.
> By default freeradius leaves /var/log/freeradius with permissions 755.
> Enabling sqltrace will result in a world-readab
Package: freeradius
Version: 1.1.7-1
Severity: grave
Tags: security
Justification: user security hole
By default freeradius leaves /var/log/freeradius with permissions 755.
Enabling sqltrace will result in a world-readable sqltrace in this,
possibly containing cleartext passwords.
Been there, don
3 matches
Mail list logo