CVE-2011-1500 Information

Description

PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user’s home directory which allows local users to obtain Pandora credentials by reading this file.

Reference

http://openwall.com/lists/oss-security/2011/04/08/2 http://openwall.com/lists/oss-security/2011/04/08/4 http://secunia.com/advisories/44059 http://www.securityfocus.com/bid/47300 https://bugs.launchpad.net/pithos/+bug/733307 https://exchange.xforce.ibmcloud.com/vulnerabilities/66661

Share on: