PT-2001-2005 · Deltathree · Deltathree Pc-To-Phone

Publicado

2001-12-06

·

Atualizado

2017-10-10

·

CVE-2001-0837

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions DeltaThree Pc-To-Phone version 3.0.3
Description The issue allows local users to read sensitive data due to its placement in world-readable locations within the installation directory. Specifically, the information can be accessed in the temp.html file, the log folder, and the PhoneBook folder.
Recommendations For DeltaThree Pc-To-Phone version 3.0.3, consider restricting access to the installation directory to prevent unauthorized reading of sensitive data. As a temporary workaround, restrict access to the temp.html file, the log folder, and the PhoneBook folder to minimize the risk of data exposure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0837

Produtos afetados

Deltathree Pc-To-Phone