PT-2006-6813 · Gnotebook · Gnotebook
Publicado
2006-12-01
·
Atualizado
2008-09-05
·
CVE-2006-6182
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNotebook version 0.7.0.1
Description
The issue concerns the storage of Gmail passwords in plaintext in a log file, specifically %SYSTEMDRIVE%tempGnotebook.txt, allowing local users to obtain these passwords by reading the file.
Recommendations
For version 0.7.0.1, consider removing or securing access to the Gnotebook.txt log file to prevent unauthorized password access. As a temporary workaround, restrict local access to the %SYSTEMDRIVE%temp directory until a more secure method of password storage is implemented.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnotebook