Inlook未授权用户密码文件访问漏洞

漏洞信息详情

Inlook未授权用户密码文件访问漏洞

漏洞简介

用于inlook 0.7.3及其早期版本的 /.inlook/.crypt文件安装时具有全域可读许可。本地用户可以利用该漏洞获得用户POP3证明。

漏洞公告

This issue was addressed in version 0.7.4.
Inlook Inlook 0.6 .0

Inlook Inlook 0.6.1

Inlook Inlook 0.6.10 0

Inlook Inlook 0.6.11

Inlook Inlook 0.6.12

Inlook Inlook 0.6.13

Inlook Inlook 0.6.14

Inlook Inlook 0.6.2

Inlook Inlook 0.6.3

Inlook Inlook 0.6.4

Inlook Inlook 0.6.5

Inlook Inlook 0.6.6

Inlook Inlook 0.6.7

Inlook Inlook 0.6.8

Inlook Inlook 0.6.9

Inlook Inlook 0.7 .0

Inlook Inlook 0.7.1

Inlook Inlook 0.7.2

Inlook Inlook 0.7.3

参考网址

来源: sourceforge.net
链接:https://sourceforge.net/project/shownotes.php?release_id=213427

来源: XF
名称: inlook-file-information-disclosure(14990)
链接:http://xforce.iss.net/xforce/xfdb/14990

来源: BID
名称: 9527
链接:http://www.securityfocus.com/bid/9527

来源: SECUNIA
名称: 10752
链接:http://secunia.com/advisories/10752/

来源: OSVDB
名称: 3771
链接:http://www.osvdb.org/3771

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享