displaying luks-passphrase unencrypted.

Bug #387688 reported by Machtin
68
This bug affects 1 person
Affects Status Importance Assigned to Milestone
usplash (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: usplash

When i boot, I'm asked for my luks-passphrase, to decrypt my /home-partition.
The password then is displayed as ******..., however, when i enter the pass and go to tty7 via ctrl+alt+f7, i can read the passphrase i just entered!
i consider this a security bug.. I'm currently running 2.6.30-9, but i've noticed this at least since 2.6.28

ProblemType: Bug
Architecture: amd64
Date: Tue Jun 16 09:10:26 2009
DistroRelease: Ubuntu 9.10
MachineType: System manufacturer System Product Name
NonfreeKernelModules: nvidia
Package: usplash 0.5.31
ProcCmdLine: root=UUID=bf519268-c204-42a8-8f10-2ebdbc68c6ba ro quiet splash
ProcEnviron:
 LANGUAGE=
 LANG=en_US.UTF-8
 SHELL=/bin/bash
ProcVersionSignature: Ubuntu 2.6.30-9.10-generic
SourcePackage: usplash
Uname: Linux 2.6.30-9-generic x86_64
UsplashConf:
 # Usplash configuration file
 # These parameters will only apply after running update-initramfs.

 xres=1280
 yres=1024
dmi.bios.date: 05/19/2009
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: 0403
dmi.board.asset.tag: To Be Filled By O.E.M.
dmi.board.name: P6T SE
dmi.board.vendor: ASUSTeK Computer INC.
dmi.board.version: Rev 1.xx
dmi.chassis.asset.tag: Asset-1234567890
dmi.chassis.type: 3
dmi.chassis.vendor: Chassis Manufacture
dmi.chassis.version: Chassis Version
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvr0403:bd05/19/2009:svnSystemmanufacturer:pnSystemProductName:pvrSystemVersion:rvnASUSTeKComputerINC.:rnP6TSE:rvrRev1.xx:cvnChassisManufacture:ct3:cvrChassisVersion:
dmi.product.name: System Product Name
dmi.product.version: System Version
dmi.sys.vendor: System manufacturer

Revision history for this message
Machtin (spamzad) wrote :
Machtin (spamzad)
visibility: private → public
Machtin (spamzad)
visibility: public → private
Kees Cook (kees)
security vulnerability: yes → no
visibility: private → public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.