Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 17 Nov 2010 23:58:36 +0100
From: Martin Drescher <drescher@...fu.de>
To: oss-security@...ts.openwall.com
Subject: Re: Clear text password in process list when using
 MySQL GUI tools

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi ML.

On 17/11/10 21:06, Moritz Muehlenhoff wrote:
> On Wed, Nov 17, 2010 at 08:38:06AM -0500, Josh Bressers wrote:
>> Steve,
>>
>> What are the thoughts of MITRE on this one? This affects all sorts of stuff,
>> and I don't upstream removing the command line option (which is probably the
>> only fix).
> 
> I didn't look into this specific issue since both mysql-query-browser
> and mysql-admin have been removed and are no longer supported in Debian,

I can't follow you with that. Those packages are part of my Debian
distribution, which is lenny and the reason I initially posted this
issue to Debian security.

> but there have been cases in the past, where leaking sensitive information
> in the process list was assigned a CVE ID, e.g. CVE-2004-1948 for
> ncftp.

Let me add that for an experienced user it should/may be clear that
command line arguments may be visible in process list or via the proc
fs. The MySQL GUI-tools _and_ mysql command line tool do in fact that
they care about sensitive information (eg. user, password, host). But
then the GUI does this epic fail calling 'mysql' through an 'xterm -e
mysql ...' call. Or some other kind of terminal. This is a kind of stupid.

> 
> Cheers,
>         Moritz

- -- 
 Martin Drescher
 Manfred-von-Richthofen-Strasse 223
 12101 Berlin

 Office:+49.(0)30.746 80 425
 Mobil: +49.(0)176 101 73 264
 Email:<drescher@...fu.de>
 USt-IdNr. DE211832267
 GnuPG Key Fingerprint, KeyID '4FBE451A':
 '2237 1E95 8E50 E825 9FE8  AEE1 6FF4 1E34 4FBE 451A'
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkzkXhYACgkQb/QeNE++RRpMhwCffUPk6ehCaW9yrdruxmEw4LEo
JZUAn0LfOhjxrUYdcrAZqP0rWG+Vuxpx
=caEx
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.