[Bug 880348] [NEW] boot cryptsetup passphrase prompt displays passphrase in clear text

ilf 880348 at bugs.launchpad.net
Sun Oct 23 13:30:45 UTC 2011


*** This bug is a security vulnerability ***

Public security bug reported:

Since updating to oneiric, plymouth displays the boot cryptsetup passphrases in the clear!
It's asterisks on the first device, which alone is a problem, see bug 778659.
Filing this new bug, since passphrases in the clear are another can of worms.

** Affects: plymouth (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to plymouth in Ubuntu.
https://bugs.launchpad.net/bugs/880348

Title:
  boot cryptsetup passphrase prompt displays passphrase in clear text

Status in “plymouth” package in Ubuntu:
  New

Bug description:
  Since updating to oneiric, plymouth displays the boot cryptsetup passphrases in the clear!
  It's asterisks on the first device, which alone is a problem, see bug 778659.
  Filing this new bug, since passphrases in the clear are another can of worms.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/plymouth/+bug/880348/+subscriptions




More information about the foundations-bugs mailing list