PT-2006-6813 · Gnotebook · Gnotebook
Published
2006-12-01
·
Updated
2008-09-05
·
CVE-2006-6182
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNotebook version 0.7.0.1
Description
The issue concerns the storage of Gmail passwords in plaintext in a log file, specifically %SYSTEMDRIVE%tempGnotebook.txt, allowing local users to obtain these passwords by reading the file.
Recommendations
For version 0.7.0.1, consider removing or securing access to the Gnotebook.txt log file to prevent unauthorized password access. As a temporary workaround, restrict local access to the %SYSTEMDRIVE%temp directory until a more secure method of password storage is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnotebook