PT-2006-6813 · Gnotebook · Gnotebook

Published

2006-12-01

·

Updated

2008-09-05

·

CVE-2006-6182

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNotebook version 0.7.0.1
Description The issue concerns the storage of Gmail passwords in plaintext in a log file, specifically %SYSTEMDRIVE%tempGnotebook.txt, allowing local users to obtain these passwords by reading the file.
Recommendations For version 0.7.0.1, consider removing or securing access to the Gnotebook.txt log file to prevent unauthorized password access. As a temporary workaround, restrict local access to the %SYSTEMDRIVE%temp directory until a more secure method of password storage is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6182

Affected Products

Gnotebook