[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
gnats/542: gnatd needs to ignore GNATSDB environ variable
From: |
bug-gnats |
Subject: |
gnats/542: gnatd needs to ignore GNATSDB environ variable |
Date: |
Mon, 21 Nov 2005 10:40:30 -0600 (CST) |
>Number: 542
>Category: gnats
>Synopsis: gnatd needs to ignore GNATSDB environ variable
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: unassigned
>State: open
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Mon Nov 21 10:40:30 -0600 2005
>Originator: Chad Walstrom <address@hidden>
>Release: 4.1.0
>Organization:
>Environment:
Debian GNU/Linux 3.1 (sarge)
>Description:
If the inetd daemon is restarted with sudo while not throwing out environment
variables, gnatsd is passed the user's GNATSDB environment variable. It then
attempts to use this information to connect and complains that there is no
database named HOST:PORT:DBNAME:USER:PASSWD.
This has a slight security risk in that the password is reported in the 417
error code sent to the GNATS client.
>How-To-Repeat:
>Fix:
Unknown
>Notify-List:
>Unformatted:
[Prev in Thread] |
Current Thread |
[Next in Thread] |
- gnats/542: gnatd needs to ignore GNATSDB environ variable,
bug-gnats <=