PT-2006-6813 · Gnotebook · Gnotebook

Publicado

2006-12-01

·

Atualizado

2008-09-05

·

CVE-2006-6182

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNotebook version 0.7.0.1
Description The issue concerns the storage of Gmail passwords in plaintext in a log file, specifically %SYSTEMDRIVE%tempGnotebook.txt, allowing local users to obtain these passwords by reading the file.
Recommendations For version 0.7.0.1, consider removing or securing access to the Gnotebook.txt log file to prevent unauthorized password access. As a temporary workaround, restrict local access to the %SYSTEMDRIVE%temp directory until a more secure method of password storage is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6182

Produtos afetados

Gnotebook