[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#512674: marked as done (leaves password in debconf database)

Your message dated Thu, 07 Jan 2010 21:33:04 +0000
with message-id <E1NSzya-0005Bk-68@ries.debian.org>
and subject line Bug#512674: fixed in aiccu 20070115-11
has caused the Debian Bug report #512674,
regarding leaves password in debconf database
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org

512674: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512674
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: aiccu
Version: 20070115-9
Severity: normal

If you look at /var/cache/debconf/passwords.dat, you'll probably
find a copy of the password in there. While the file is only
readable by root, this is an unnecessary way to leak the

Best practice for password prompting with debconf is to call
db_reset to clear the password out of the database as soon
as possible after you use it.

-- System Information:
Debian Release: 5.0
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.27-1-686 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages aiccu depends on:
ii  debconf                     1.5.24       Debian configuration management sy
ii  iproute                     20080725-2   networking and traffic control too
ii  iputils-ping                3:20071127-1 Tools to test the reachability of 
ii  iputils-tracepath           3:20071127-1 Tools to trace the network path to
ii  libc6                       2.7-18       GNU C Library: Shared libraries
ii  libgnutls26                 2.4.2-4      the GNU TLS library - runtime libr
ii  lsb-base                    3.2-20       Linux Standard Base 3.2 init scrip

Versions of packages aiccu recommends:
ii  ntpdate                 1:4.2.4p4+dfsg-8 client for setting system time fro

aiccu suggests no packages.

-- debconf information excluded

see shy jo

Attachment: signature.asc
Description: Digital signature

--- End Message ---
--- Begin Message ---
Source: aiccu
Source-Version: 20070115-11

We believe that the bug you reported is fixed in the latest version of
aiccu, which is due to be installed in the Debian FTP archive:

  to main/a/aiccu/aiccu_20070115-11.diff.gz
  to main/a/aiccu/aiccu_20070115-11.dsc
  to main/a/aiccu/aiccu_20070115-11_i386.deb

A summary of the changes between this version and the previous one is

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 512674@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
Reinier Haasjes <reinier@haasjes.com> (supplier of updated aiccu package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)

Hash: SHA1

Format: 1.8
Date: Wed, 06 Jan 2010 10:02:24 +0100
Source: aiccu
Binary: aiccu
Architecture: source i386
Version: 20070115-11
Distribution: unstable
Urgency: low
Maintainer: Reinier Haasjes <reinier@haasjes.com>
Changed-By: Reinier Haasjes <reinier@haasjes.com>
 aiccu      - SixXS Automatic IPv6 Connectivity Client Utility
Closes: 512674 529185 531003 559683 561324 562803
 aiccu (20070115-11) unstable; urgency=low
   * New maintainer. (Closes: #529185: ITA: aiccu -- SixXS Automatic IPv6
     Connectivity Client Utility)
   * Install aiccu.conf to usr/share/aiccu/conf-templates/
     and use in postinst (Closes: #559683) - Thanks to Patrick Schoenfeld
   * Fix "leaves password in debconf database" add db_reset to postinst
     (Closes: #512674)
   * Fix "tunnel does not survive suspend" Add restart script to
     /etc/pm/sleep.d (Closes: #531003)
   * Added Japanese translation (Closes: #562803) - Thanks to Hideki Yamane
   * Fix "uses non-essential tools in the config script" (Closes: #561324)
     - get brokers list by dns (instead of own binary)
     - supply static brokerlist if dns is unavailable
     - get tunnel ID in postinst (using own binary)
   * Minimize rules file - Thanks to Patrick Schoenfeld
   * Added VCS-Headers
   * Fixed spelling-error-in-binary
   * Fixed maintainer-script-empty preinst
   * Fixed maintainer-script-without-set-e postinst
   * Upgraded compat version to 7
   * Added debian/README.source
   * Upgraded standards-version to 3.8.3
   * Added "no-upstream-changelog" to lintian-overrides
   * Add dependency on ucf
 2e38ca6c2b391a7b5e68a84a4ef2a33918534cec 1128 aiccu_20070115-11.dsc
 123233e0e202e4fe87441950341500823da03c59 23487 aiccu_20070115-11.diff.gz
 f36e0dc9830c002c648c32c0d427dd496b240d44 47656 aiccu_20070115-11_i386.deb
 f0a0f2dce5f9c629aa6940ce51972d5329edbca904bbb817c947c9849d2d5e17 1128 aiccu_20070115-11.dsc
 e036d67859552d3e4fb601a8f3ac94d695f9667f52328fcf27c63536f1200078 23487 aiccu_20070115-11.diff.gz
 9a98deb945d4a2721b580c10b21cf75797b64d9ed907783f9b86ba4fa49fe3ec 47656 aiccu_20070115-11_i386.deb
 ad9b9e8488d6adec83baa29c7ff7d2dc 1128 net optional aiccu_20070115-11.dsc
 645bde58455ca0b2585e0f0f8d000f05 23487 net optional aiccu_20070115-11.diff.gz
 bb9ac22f98dd5e6f096d538eb841caa8 47656 net optional aiccu_20070115-11_i386.deb

Version: GnuPG v1.4.10 (GNU/Linux)


--- End Message ---

Reply to: