Bug#993935: debian-edu-ltsp-install: Netboot image exposes private data and crypto keys

2021-09-08 Thread Wolfgang Schweer
[ Dominik George, 2021-09-08 ] > Package: debian-edu-config > Version: 2.11.56 > Severity: critical > Tags: security > Justification: root security hole > X-Debbugs-Cc: Debian Security Team > > The LTSP netboot image produced by debian-edu-ltsp-install includes full > copies > of files that shou

Bug#993935: debian-edu-ltsp-install: Netboot image exposes private data and crypto keys

2021-09-08 Thread Dominik George
Package: debian-edu-config Version: 2.11.56 Severity: critical Tags: security Justification: root security hole X-Debbugs-Cc: Debian Security Team The LTSP netboot image produced by debian-edu-ltsp-install includes full copies of files that should never leave the Debian Edu main server, if run on