cryptsetup password displayed in plain text

Bug #366914 reported by Zeyelth
256
Affects Status Importance Assigned to Milestone
cryptsetup (Ubuntu)
New
Undecided
Unassigned

Bug Description

What happened:
A typo in /etc/fstab sent me to the console after entering the passwords for my encrypted disks, where one of the passwords was displayed in plain text.

What I expected to happen:
Not seeing my password echoed in the console.

Long explanation:
I have two disks which are both using LVM/encryption as per the Ubuntu alternative installer's (mini.iso) Guided Setup. I installed Ubuntu (9.04) on one of the drives, and kept the other drive as is (it was already encrypted). After booting the system, I proceeded to set up /etc/crypttab and /etc/fstab so that it would mount the other disk as well upon boot. When editing /etc/fstab, I made a typo (provided the wrong UUID) which resulted in the boot process asking for the password to my system disk, followed by my other disk. It accepted both passwords, but due to the typo in /etc/fstab, was unable to mount the second disk, which resulted in me being sent to the console, instead X. The console showed the entered password for the second (last) drive in plain text, which is definitely not wanted behaviour. It shouldn't be echoed at all.

visibility: private → public
affects: ubuntu → cryptsetup (Ubuntu)
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.