Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Daniel Moerner

#48775de 53,635
5CVSS total
Vulnerabilidades · 1
PT-2019-6498
5.0
2019-11-07
Firegpg · Firegpg · CVE-2008-7272
**Name of the Vulnerable Software and Affected Versions** FireGPG versions prior to 0.6 **Description** The issue concerns the insecure handling of a user's passphrase and decrypted cleartext by FireGPG. Specifically, it writes pre-encrypted cleartext and the user's passphrase to disk, which may compromise secure communication or a user's private key. **Recommendations** For FireGPG versions prior to 0.6, update to version 0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and avoiding the use of FireGPG for secure communication until the update is applied.