[Bug 1738581] Re: apport is leaking environment variables (including passwords!) to public bug reports

Brian Murray brian at ubuntu.com
Wed Mar 28 21:04:28 UTC 2018


** Also affects: apport (Ubuntu Artful)
   Importance: Undecided
       Status: New

** Also affects: apport (Ubuntu Xenial)
   Importance: Undecided
       Status: New

** Changed in: apport (Ubuntu Xenial)
       Status: New => Triaged

** Changed in: apport (Ubuntu Artful)
       Status: New => Triaged

** Changed in: apport (Ubuntu Xenial)
   Importance: Undecided => High

** Changed in: apport (Ubuntu Artful)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apport in Ubuntu.
https://bugs.launchpad.net/bugs/1738581

Title:
  apport is leaking environment variables  (including passwords!) to
  public bug reports

Status in apport package in Ubuntu:
  Fix Released
Status in apport source package in Xenial:
  Triaged
Status in apport source package in Artful:
  Triaged

Bug description:
  See the bug report https://bugs.launchpad.net/ubuntu/+source/evolution/+bug/1738564
  created with ubuntu-bug.

  Apport includes the file JournalErrors.txt
  This file includes e.g. the following line.
  Dez 16 19:11:31 hostname /usr/lib/gdm3/gdm-x-session[9679]: dbus-update-activation-environment: setting MPD_HOST=xxxxxxx at xxxx.xxxxxxxxxxx.org

  
  Normally it would be not problem that gdm-x-session write this to the journal, because the journal is not intended to be published on the internet. 

  Setting confidential informations via environment is maybe not the
  best idea, but a legal procedure and for `mpc` the only way to set
  this information.

  IMHO the apport utility is here the problem, because it includes the
  file with risky information to a public visible bug report.

  
  Note: I manually delete the attachment in the mentioned bug report. But how can I sure that a web crawlser hasn't read/preserved that attachment?

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1738581/+subscriptions



More information about the foundations-bugs mailing list