Pithos 'pithos.ini' Local Information Disclosure Vulnerability
BID:47300
Info
Pithos 'pithos.ini' Local Information Disclosure Vulnerability
| Bugtraq ID: | 47300 |
| Class: | Design Error |
| CVE: |
CVE-2011-1500 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 11 2011 12:00AM |
| Updated: | Apr 15 2011 09:34PM |
| Credit: | Ian Daniher |
| Vulnerable: |
Pithos Pithos 0.3.7 |
| Not Vulnerable: |
Pithos Pithos 0.3.8 |
Discussion
Pithos 'pithos.ini' Local Information Disclosure Vulnerability
Pithos is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Pithos 0.3.7 is vulnerable; other versions may also be affected.
Pithos is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Pithos 0.3.7 is vulnerable; other versions may also be affected.
Exploit / POC
Pithos 'pithos.ini' Local Information Disclosure Vulnerability
Attackers can use readily available commands to exploit this issue.
Attackers can use readily available commands to exploit this issue.
Solution / Fix
Pithos 'pithos.ini' Local Information Disclosure Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Pithos Pithos 0.3.7
Solution:
The vendor released an update. Please see the references for details.
Pithos Pithos 0.3.7
-
Pithos pithos_0.3.8.tgz
http://kevinmehall.net/p/pithos/release/pithos_0.3.8.tgz
References
Pithos 'pithos.ini' Local Information Disclosure Vulnerability
References:
References:
- password stored in plaintext in $HOME/.config/pithos.ini (Launchpad)
- Product Homepage (Pithos)