oss-sec mailing list archives

Re: CVE request: improper permissions on ~/.qtnx/*.nxml


From: Josh Bressers <bressers () redhat com>
Date: Fri, 12 Aug 2011 14:43:03 -0400 (EDT)



----- Original Message -----
A Debian bug report noted that qtnx stores its configuration file
insecurely. If a non-default SSH key is used, the key is stored in
this
world-readable file (~/.qtnx/*.nxml) in a world-readable directory
(~/.qtnx/).

Could a CVE be assigned to this please?

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=637439
https://bugzilla.redhat.com/show_bug.cgi?id=730081


Please use CVE-2011-2916

Thanks.

-- 
    JB


Current thread: