oss-sec mailing list archives

CVE request: improper permissions on ~/.qtnx/*.nxml


From: Vincent Danen <vdanen () redhat com>
Date: Thu, 11 Aug 2011 11:49:49 -0600

A Debian bug report noted that qtnx stores its configuration file
insecurely.  If a non-default SSH key is used, the key is stored in this
world-readable file (~/.qtnx/*.nxml) in a world-readable directory
(~/.qtnx/).

Could a CVE be assigned to this please?

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=637439
https://bugzilla.redhat.com/show_bug.cgi?id=730081

--
Vincent Danen / Red Hat Security Response Team

Current thread: