CVE-2005-0625: Low severity Debian Reportbug vulnerability
Published Feb 28, 2005
·Updated
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
Affected Software
3 affected components
Debian Reportbug=2.60
Debian Reportbug=2.61
Debian Reportbug=3.2
Remediation
Patch Available
Event History
Feb 28, 2005
CVE Published
05:00 AM
Mar 2, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0625?
CVE-2005-0625 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2005-0625?
To fix CVE-2005-0625, users should upgrade to a version of Reportbug that is not 3.2, 2.60, or 2.61.
3
What information is exposed in CVE-2005-0625?
CVE-2005-0625 exposes sensitive information from the .reportbugrc file, including smtpuser and smtppasswd.
4
What versions of Reportbug are affected by CVE-2005-0625?
CVE-2005-0625 affects Reportbug versions 2.60, 2.61, and 3.2.
5
Are there any workarounds for CVE-2005-0625?
A possible workaround for CVE-2005-0625 is to temporarily remove sensitive data from the .reportbugrc file before using Reportbug.