Cocktail · Cocktail · CVE-2005-1387
Name of the Vulnerable Software and Affected Versions:
Cocktail versions 3.5.4 and earlier
Description:
The issue allows local users to gain sensitive information by running a process listing, as the administrative password is passed to `sudo` in cleartext.
Recommendations:
For versions 3.5.4 and earlier, consider restricting access to the `sudo` command until a fix is available, or avoid running process listings that could expose sensitive information.