Bug#472965: open-iscsi: iscsid.conf world readable

2008-03-27 Thread root
Package: open-iscsi Version: 2.0.865-1 Severity: grave Tags: security Justification: user security hole /etc/iscsi/iscsid.conf is world readable. When putting password in the file it can be read by all users. -- System Information: Debian Release: 4.0 APT prefers stable APT policy: (500,

Bug#472965: open-iscsi: iscsid.conf world readable

2008-03-27 Thread Rudy Gevaert
Thijs Kinkhorst wrote: On Thursday 27 March 2008 16:02, root wrote: /etc/iscsi/iscsid.conf is world readable. When putting password in the file it can be read by all users. Thank you for your support. It is indeed true that the file is world-readable, but as it doesn't contain any

Bug#472965: open-iscsi: iscsid.conf world readable

2008-03-27 Thread Thijs Kinkhorst
severity 472965 wishlist thanks Hi, On Thursday 27 March 2008 16:02, root wrote: /etc/iscsi/iscsid.conf is world readable. When putting password in the file it can be read by all users. Thank you for your support. It is indeed true that the file is world-readable, but as it doesn't contain