CVE-2007-6418

The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=448519 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=448519 -
References () http://osvdb.org/44138 - () http://osvdb.org/44138 -
References () http://secunia.com/advisories/29059 - () http://secunia.com/advisories/29059 -
References () http://www.debian.org/security/2008/dsa-1501 - () http://www.debian.org/security/2008/dsa-1501 -
References () http://www.securityfocus.com/bid/27938 - () http://www.securityfocus.com/bid/27938 -

Information

Published : 2007-12-18 00:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6418

Mitre link : CVE-2007-6418

CVE.ORG link : CVE-2007-6418


JSON object : View

Products Affected

debian

  • debian_linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor