Bug#609919: mumble-server creates world readable config file
Patrick Matthäi
pmatthaei at debian.org
Thu Jan 13 20:22:16 UTC 2011
severity #609919 grave
thanks
Am 13.01.2011 21:09, schrieb Felix Geyer:
> Package: mumble-server
> Version: 1.2.2-5
>
> mumble-server creates the config file /etc/mumble-server.ini
> and sets the permissions to 0644 which allows every user to read it.
>
> As the server password is stored in this config file it would
> be much better to set the owner to root:mumble-server and the
> permissions to 0640.
Whops, this issue is grave and fixed in svn.
More information about the Pkg-voip-maintainers
mailing list