*** This bug is a security vulnerability *** Public security bug reported:
References: DSA-1501-1 (http://www.debian.org/security/2008/dsa-1501) Quoting: "Tobias Gruetzmacher discovered that a Debian-provided CRON script in dspam, a statistical spam filter, included a database password on the command line when using the MySQL backend. This allowed a local attacker to read the contents of the dspam database, such as emails." ** Affects: ubuntu Importance: Undecided Status: New ** Affects: debian Importance: Unknown Status: Unknown ** Visibility changed to: Public ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2007-6418 ** Bug watch added: Debian Bug tracker #448519 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=448519 ** Also affects: debian via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=448519 Importance: Unknown Status: Unknown -- [dspam] [CVE-2007-6418] programming error leading to information disclosure https://bugs.launchpad.net/bugs/195691 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
