[Secure-testing-team] Bug#789543: CVE-2015-3248

Moritz Muehlenhoff jmm at debian.org
Mon Jun 22 07:16:58 UTC 2015


Source: openhpi
Severity: important
Tags: security

Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3248

On Debian /var/lib/openhpi/ isn't world-writable, but still
world-readable. Can you investigate whether that's a real issue
or otherwise mitigated in the Debian packagin?

Cheers,
        Moritz



More information about the Secure-testing-team mailing list