Vulnonym.org

CVE-2008-2517 - Poor spirited Airplanes

Description

The sarab.sh script in SaraB before 0.2.4 places the dar program’s encryption key on the command line which allows local users to obtain sensitive information by listing the process.

Reference

http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?r1=34&r2=36 http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?view=log http://sourceforge.net/project/shownotes.php?release_id=601603&group_id=91804 http://www.securityfocus.com/bid/29364 http://secunia.com/advisories/30394 http://www.vupen.com/english/advisories/2008/1659/references https://exchange.xforce.ibmcloud.com/vulnerabilities/42621