Description
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
Affected products
- Debian / reportbug2.60 – 2.60
- Debian / reportbug2.61 – 2.61
References
- VENDOR_ADVISORYhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407
- VENDOR_ADVISORYhttps://bugzilla.ubuntu.com/show_bug.cgi?id=6600
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/19504
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110972153627388&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/14422/