Description
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
Affected products
- Debian / reportbug2.60 – 2.60
- Debian / reportbug2.61 – 2.61
- Debian / reportbug3.2 – 3.2
References
- VENDOR_ADVISORYhttps://bugzilla.ubuntu.com/show_bug.cgi?id=6600
- VENDOR_ADVISORYhttps://bugzilla.ubuntu.com/show_bug.cgi?id=6717
- VENDOR_ADVISORYhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/19520
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110972153627388&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/14422/