ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2013-1425 | third party advisory |
https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1096253.html | |
https://github.com/elmar/ldap-git-backup/commit/a90f3217fce87962db82d212f73af70693087124 | third party advisory patch |