Back to search
CVE-2008-2517
Published: Jun 3, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the process.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
sarab-ciphers-information-disclosure(42621)
vdb-entry
x_refsource_XF
http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?r1=34&r2=36
x_refsource_CONFIRM
http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?view=log
x_refsource_CONFIRM
ADV-2008-1659
vdb-entry
x_refsource_VUPEN
29364
vdb-entry
x_refsource_BID
30394
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now