#724652 ekeyd: reportbug accesses secret keyring

Package:
ekeyd
Source:
ekeyd
Description:
Simtec Electronics UDEKEY01 Entropy Key Daemon
Submitter:
Thorsten Glaser
Date:
2013-09-30 21:45:05 UTC
Severity:
important
#724652#5
Date:
2013-09-26 08:56:48 UTC
From:
To:
As seen in <20130925220319.21947.49284.reportbug@heisenberg.scientia.net>
trying to report a bug against ekeyd will, given suitable permissions,
disclose the contents of the keyring. If not, we at least get

but this is a secret key disclosure.

bye,
//mirabilos

#724652#10
Date:
2013-09-30 20:17:35 UTC
From:
To:
I'm afraid that reportbug has no mechanism for excluding modified
conffiles from being included in the bug report.

The only thing I can advise is that users never ever run reportbug as
root, and that they should be aware of the contents of the email they
are sending.

Indeed, if run as root, reportbug will prompt the user to continue,
having first printed:

   "Running 'reportbug' as root is probably insecure!"

The user is then asked whether they wish to continue.

#724652#15
Date:
2013-09-30 21:37:04 UTC
From:
To:
Paul Martin dixit:

Oh, okay.

Right, he is. Maybe I shouldn’t do this in the future
then either…

Thanks for answering, and no problem if this is nothing
you can do anything about… although maybe the file should
just not be a conffile then?

bye,
//mirabilos