gnats-prs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

gnats/542: gnatd needs to ignore GNATSDB environ variable


From: bug-gnats
Subject: gnats/542: gnatd needs to ignore GNATSDB environ variable
Date: Mon, 21 Nov 2005 10:40:30 -0600 (CST)

>Number:         542
>Category:       gnats
>Synopsis:       gnatd needs to ignore GNATSDB environ variable
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    unassigned
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Nov 21 10:40:30 -0600 2005
>Originator:     Chad Walstrom <address@hidden>
>Release:        4.1.0
>Organization:
>Environment:
Debian GNU/Linux 3.1 (sarge)
>Description:
If the inetd daemon is restarted with sudo while not throwing out environment 
variables, gnatsd is passed the user's GNATSDB environment variable.  It then 
attempts to use this information to connect and complains that there is no 
database named HOST:PORT:DBNAME:USER:PASSWD.

This has a slight security risk in that the password is reported in the 417 
error code sent to the GNATS client.
>How-To-Repeat:
>Fix:
Unknown
>Notify-List:    
>Unformatted:





reply via email to

[Prev in Thread] Current Thread [Next in Thread]