PT-2002-1439 · Gaim · Gaim
Publicado
2002-05-29
·
Atualizado
2016-10-18
·
CVE-2002-0377
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gaim version 0.57
Description
The issue allows local users to access sensitive information, including MSN web email accounts of other users, by reading authentication data from files in the /tmp directory. This is possible because Gaim stores sensitive information in world-readable and group-writable files.
Recommendations
For Gaim version 0.57, consider restricting access to the /tmp directory or modifying the file permissions to prevent unauthorized access until a patch is available. As a temporary workaround, avoid using Gaim to access MSN web email accounts until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gaim