Lucene search

K
cve[email protected]CVE-2010-0119
HistoryFeb 25, 2010 - 12:30 a.m.

CVE-2010-0119

2010-02-2500:30:00
CWE-200
web.nvd.nist.gov
23
bournal
freebsd
security vulnerability
information disclosure
cve-2010-0119

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to “echoing.”

Affected configurations

NVD
Node
becauseinterbournalRange1.4
OR
becauseinterbournalMatch0.1
OR
becauseinterbournalMatch0.2
OR
becauseinterbournalMatch0.3
OR
becauseinterbournalMatch0.4
OR
becauseinterbournalMatch0.4.5
OR
becauseinterbournalMatch0.6
OR
becauseinterbournalMatch0.7
OR
becauseinterbournalMatch0.8
OR
becauseinterbournalMatch0.9
OR
becauseinterbournalMatch1.0
OR
becauseinterbournalMatch1.1
OR
becauseinterbournalMatch1.2
OR
becauseinterbournalMatch1.3
AND
freebsdfreebsdMatch8.0

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%