[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#521298: marked as done (akregator exposes password of password protected blogs)



Your message dated Thu, 18 Jan 2018 16:06:31 +0100
with message-id 
and subject line Re: akregator exposes password of password protected blogs
has caused the Debian Bug report #521298,
regarding akregator exposes password of password protected blogs
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
521298: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521298
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: akregator
Version: 4:3.5.9-5
Severity: important

I subscribed to a password protected blog using a feed URL like this
one:

http://user:password@passwordprotected-blog.example.com/blog/index.rss



Under $HOME/.kde/share/apps/akregator/Archive/ akregator creates a
file, the name containing not only the feed URL but also the username
and password


This may expose passwords to other users of the box. 


-- System Information:
Debian Release: 5.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686 (SMP w/1 CPU core)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages akregator depends on:
ii  kdelibs4c2a      4:3.5.10.dfsg.1-0lenny1 core libraries and binaries for al
ii  libc6            2.7-18                  GNU C Library: Shared libraries
ii  libgcc1          1:4.3.2-1.1             GCC support library
ii  libkdepim1a      4:3.5.9-5               KDE PIM library
ii  libqt3-mt        3:3.3.8b-5+b1           Qt GUI Library (Threaded runtime v
ii  libstdc++6       4.3.2-1.1               The GNU Standard C++ Library v3

akregator recommends no packages.

akregator suggests no packages.

-- no debconf information



--- End Message ---
--- Begin Message ---
Dear bug submitter,

Thank you for reporthing this issue.  The bug has been determined not to be
Debian specific, and therefore was reported in the KDE bugtracker; see
https://bugs.kde.org/show_bug.cgi?id=190058.

We are sorry it has not been resolved.  However, the version in which the
issue was reported is now obsolete and the upstream tracker has closed the
issue. Thus we are also closing the issue in Debian bug tracker.

If you think the bug is still relevant to a KDE Pim version in Debian stable
(aka Stretch) or newer -- i.e. part of KDE Applications 15.08.0 or newer --
then please open a new bugreport upstream and add your new information in the
upstream bugreport.

Again, thank you for reporting the issue. If there are any questions feel free
to ask.

KDE upstream bug tracker closed their bug with following statement:

"This bug has only been reported for versions before 15.08.0, which have been
unsupported for at least two years now. Can anyone tell if this bug still
present?

If noone confirms this bug for a Framework-based version of kontact
(version 5.0 or later, as part of KDE Applications 15.08 or later),
it gets closed in about three months.

Just as announced in my last comment, I close this bug.
If you encounter it again in a recent version (at least 5.0 aka 15.08),
please open a new one unless it already exists. Thank you for all your input."

--- End Message ---

Reply to: