QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
BID:49128
Info
QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
| Bugtraq ID: | 49128 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 11 2011 12:00AM |
| Updated: | May 07 2015 05:16PM |
| Credit: | Vincent Danen |
| Vulnerable: |
qtnx qtnx 0.9-3 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
qtnx is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information. Information obtained may aid in further attacks.
qtnx 0.9-3 is vulnerable; other versions may also be affected.
qtnx is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information. Information obtained may aid in further attacks.
qtnx 0.9-3 is vulnerable; other versions may also be affected.
Exploit / POC
QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
QT client qtnx '~/.qtnx/*.nxml' Insecure File Permissions Vulnerability
References:
References:
- Fedora Homepage (RedHat)
- qtnx Download page (QT client)
- Bug 730081 - freenx-client: qtnx stores configuration, including non-default aut (Vincent Danen )
- qtnx: stores keys world readable (Christoph Anton Mitterer)