PT-2019-6655 · Qtnx · Qtnx
Publicado
2019-11-15
·
Atualizado
2019-11-22
·
CVE-2011-2916
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
qtnx version 0.9
Description
The issue concerns the storage of non-custom SSH keys in a world-readable configuration file by qtnx. This could allow another local system user to obtain the private key used for remote NX sessions if a user's home directory is world-readable or world-executable.
Recommendations
For qtnx version 0.9, consider restricting access to the configuration file containing the SSH keys to prevent other local users from reading it. As a temporary workaround, restrict home directory permissions to prevent other users from accessing the private key.
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qtnx