reportbug prior to 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
debian reportbug 2.60 |
||
debian reportbug 2.61 |