Eject Information Disclosure Vulnerability
BID:6914
Info
Eject Information Disclosure Vulnerability
| Bugtraq ID: | 6914 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 22 2002 12:00AM |
| Updated: | Nov 22 2002 12:00AM |
| Credit: | This issue was announced by the vendor in the product changelog. |
| Vulnerable: |
Eject Eject 2.0.12 Eject Eject 2.0.11 Eject Eject 2.0.10 |
| Not Vulnerable: |
Eject Eject 2.0.13 |
Discussion
Eject Information Disclosure Vulnerability
A vulnerability has been reported in the Eject utility which may be exploited to obtain sensitive information. This vulnerability can be exploited by supplying the eject utility a sensitive file as an argument. When processed eject may return sensitive information regarding the existence of the file.
This issue could be exploited by a malicious local user to gain information about the existence of files which reside in sensitive and typically unreadable locations.
A vulnerability has been reported in the Eject utility which may be exploited to obtain sensitive information. This vulnerability can be exploited by supplying the eject utility a sensitive file as an argument. When processed eject may return sensitive information regarding the existence of the file.
This issue could be exploited by a malicious local user to gain information about the existence of files which reside in sensitive and typically unreadable locations.
Exploit / POC
Eject Information Disclosure Vulnerability
No exploit is required.
No exploit is required.