Page 2 of 6 results (0.010 seconds)

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 0

Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and configuration data by reading a file. Mumble v1.2.3 y anteriores usa los permisos "world-readable" en los ficheros .local/share/data/Mumble/.mumble.sqlite en los directorios home, lo que podría permitir a usuarios locales obtener una contraseña en texto plano y los datos de configuración mediante la lectura de dichos archivos. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659039 http://bugs.gentoo.org/show_bug.cgi?id=403939 http://secunia.com/advisories/47951 http://www.debian.org/security/2012/dsa-2411 http://www.openwall.com/lists/oss-security/2012/02/15/1 http://www.openwall.com/lists/oss-security/2012/02/15/2 http://www.securityfocus.com/bid/52024 https://bugs.launchpad.net/ubuntu/+source/mumble/+bug/783405 https://bugzilla.redhat.com/show_bug.cgi?id=791000 https:/ • CWE-310: Cryptographic Issues •