PT-2017-18731 · None · Metadata Anonymisation Toolkit
Sajolida
·
Publicado
2017-05-22
·
Atualizado
2017-06-08
·
CVE-2017-9149
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Metadata Anonymisation Toolkit (MAT) versions 0.6 through 0.6.1
Description
The issue allows context-dependent attackers to obtain sensitive information by reading a file for which cleaning had been attempted, due to the silent failure of the "Clean metadata" actions when invoked from the Nautilus contextual menu.
Recommendations
For Metadata Anonymisation Toolkit (MAT) versions 0.6 through 0.6.1, consider disabling the invocation of "Clean metadata" actions from the Nautilus contextual menu until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Metadata Anonymisation Toolkit