bug marked as a duplicate of a private bug is marked as public itself

Bug #354634 reported by Jan Claeys
252
Affects Status Importance Assigned to Milestone
Launchpad itself
Won't Fix
Undecided
Unassigned

Bug Description

After reporting bug #354185 (usplash crash) and waiting some time, the apport retracing service came by and decided this was a duplicate of bug #350250, then it changed the bug from private to public. Now, bug #350250 is apparently marked private, so I can't view it, I suppose there is a possible security issue with this crash.

But isn't it a security problem then that the duplicate bugs are marked public?
A possible attacker can scan launchpad for all bugs that are marked as duplicates of private bugs, and analyse the public duplicates to determine if they can use them...

Tags: lp-bugs
affects: launchpad → malone
Revision history for this message
Eleanor Berger (intellectronica) wrote :

It is up to bug reporters and supervisors to make sure all the bugs that need to be private are so. Often the only reason to hide a bug is to hide some information that is found in the comments, for example.

Changed in malone:
status: New → Won't Fix
Revision history for this message
Jan Claeys (janc) wrote :

That means that possibly sensitive information will be publicly available because reporters often won't see that the bug privacy status got changed to public automaticly or even more often they don't have the skills to know what needs to be private... (and in case it's a common crasher bug, no developer is going to set 100 bugs back to private manually instead of fixing the bug).

I still think duplicate bugs should have the same private/public status as the main bug, just to be safe...

Revision history for this message
Karl Fogel (kfogel) wrote :

See also bug #373683 ("Leaks summary of private bug when another bug marked as a duplicate"), which is related though not exactly the same.

William Grant (wgrant)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.