PT-2005-2183 · Musicmatch · Musicmatch

Robert Fly

·

Publicado

2005-04-18

·

Atualizado

2016-10-18

·

CVE-2005-1167

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Musicmatch versions 10.00.2047 and earlier
Description The issue allows local users to potentially obtain sensitive information because log files are stored in the Program Files directory instead of the user profile.
Recommendations For Musicmatch versions 10.00.2047 and earlier, consider changing the log file storage location to the user profile directory to minimize the risk of sensitive information disclosure.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1167

Produtos afetados

Musicmatch