PT-2019-6655 · Qtnx · Qtnx

Publicado

2019-11-15

·

Atualizado

2019-11-22

·

CVE-2011-2916

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions qtnx version 0.9
Description The issue concerns the storage of non-custom SSH keys in a world-readable configuration file by qtnx. This could allow another local system user to obtain the private key used for remote NX sessions if a user's home directory is world-readable or world-executable.
Recommendations For qtnx version 0.9, consider restricting access to the configuration file containing the SSH keys to prevent other local users from reading it. As a temporary workaround, restrict home directory permissions to prevent other users from accessing the private key.

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2916

Produtos afetados

Qtnx