Search

published date: February 28, 2005

CVE-2005-0624 : reportbug before 2.62 creates...

Description

reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.

Product(s):

  • Debian reportbug 2.60
  • Debian reportbug 2.61

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2005-0624, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2005-0624 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?