Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sonderling

#38303of 53,632
7.2Total CVSS
Vulnerabilities · 1
PT-2005-2387
7.2
2005-05-02
Cocktail · Cocktail · CVE-2005-1387
Name of the Vulnerable Software and Affected Versions: Cocktail versions 3.5.4 and earlier Description: The issue allows local users to gain sensitive information by running a process listing, as the administrative password is passed to `sudo` in cleartext. Recommendations: For versions 3.5.4 and earlier, consider restricting access to the `sudo` command until a fix is available, or avoid running process listings that could expose sensitive information.