RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
BID:65264
Info
RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
| Bugtraq ID: | 65264 |
| Class: | Design Error |
| CVE: |
CVE-2014-1835 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 14 2014 12:00AM |
| Updated: | Jan 14 2014 12:00AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: |
Pedro Del Gallego echor 0.1.6 |
| Not Vulnerable: | |
Discussion
RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
echor is prone to a local remote information-disclosure vulnerability.
Local attackers may exploit this issue to obtain sensitive information, such as credentials, that may aid in further attacks.
echor 0.1.6 is vulnerable; other versions may also be affected.
echor is prone to a local remote information-disclosure vulnerability.
Local attackers may exploit this issue to obtain sensitive information, such as credentials, that may aid in further attacks.
echor 0.1.6 is vulnerable; other versions may also be affected.
Exploit / POC
RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
Attackers require local interactive access to an affected computer to exploit this issue.
Attackers require local interactive access to an affected computer to exploit this issue.
Solution / Fix
RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
RubyGems echor Plaintext Credential Local Information Disclosure Vulnerability
References:
References:
- echor 0.1.6 Ruby Gem exposes login credentials (Larry W. Cashdollar)
- echor Product Page (Pedro Del Gallego)