Bug#632598: grub-mkconfig: should set safer permissions even when hashed passwords are found

Francesco Poli invernomuto at paranoici.org
Sun Feb 24 16:40:39 UTC 2013


On Tue, 5 Jul 2011 18:44:41 +0200 Francesco Poli wrote:

> On Mon, 04 Jul 2011 00:44:12 +0200 Vladimir 'φ-coder/phcoder' Serbinenko wrote:
> 
> > On 03.07.2011 23:33, Francesco Poli (wintermute) wrote:
> > > Please apply and/or forward to upstream, as appropriate.
> > Upstream always uses stricter permissions independently of its contents.
> > I would recommend simply dropping debian patch
> 
> Or maybe amending the Debian patch with my patch...

Hello, is there any progress on this bug (#632598)?

There seems to be no visible progress in a long time.
And the bug is still reproducible.

Since this is a security problem, I consider this as somewhat urgent.

Please apply my patch or, anyway, fix the issue.
Thanks for your time.

-- 
 http://www.inventati.org/frx/frx-gpg-key-transition-2010.txt
 New GnuPG key, see the transition document!
..................................................... Francesco Poli .
 GnuPG key fpr == CA01 1147 9CD2 EFDF FB82  3925 3E1C 27E1 1F69 BFFE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 836 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-grub-devel/attachments/20130224/685dea81/attachment.pgp>


More information about the Pkg-grub-devel mailing list