[Secure-testing-team] Bug#702905: almanah: Almanah doesn't encrypt the database
Angel Abad
angel at debian.org
Tue Mar 12 19:28:19 UTC 2013
Package: almanah
Version: 0.9.0-2
Severity: grave
Tags: security upstream
Justification: user security hole
Dear Maintainer,
GApplication doesn't use "quit_mainloop" event since GIO 2.32[1], so Almanah
doesn't encrypt the database[2] when the user close the application.
Cheers,
-- System Information:
Debian Release: 7.0
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=es_ES.utf8, LC_CTYPE=es_ES.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Versions of packages almanah depends on:
ii dconf-gsettings-backend [gsettings-backend] 0.12.1-3
ii gconf-service 3.2.5-1+build1
ii libatk1.0-0 2.4.0-2
ii libc6 2.13-38
ii libcairo-gobject2 1.12.2-3
ii libcairo2 1.12.2-3
ii libcryptui0a 3.2.2-1
ii libebook-1.2-13 3.4.4-3
ii libecal-1.2-11 3.4.4-3
ii libedataserver-1.2-16 3.4.4-3
ii libedataserverui-3.0-1 3.4.4-3
ii libgconf-2-4 3.2.5-1+build1
ii libgdk-pixbuf2.0-0 2.26.1-1
ii libglib2.0-0 2.33.12+really2.32.4-5
ii libgpg-error0 1.10-3.1
ii libgpgme11 1.2.0-1.4
ii libgtk-3-0 3.4.2-6
ii libgtkspell-3-0 3.0.0~hg20110814-1
ii libical0 0.48-2
ii libpango1.0-0 1.30.0-1
ii libsoup2.4-1 2.38.1-2
ii libsqlite3-0 3.7.15.2-1
ii libxml2 2.8.0+dfsg1-7+nmu1
Versions of packages almanah recommends:
ii seahorse 3.4.1-2
almanah suggests no packages.
-- no debconf information
More information about the Secure-testing-team
mailing list