CVE-2010-0119

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/02/2010
Last modified:
11/04/2025

Description

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:becauseinter:bournal:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:a:becauseinter:bournal:0.1:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.2:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.3:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.4:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.4.5:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.6:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.7:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.8:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:0.9:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:1.0:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:1.1:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:1.2:*:*:*:*:*:*:*
cpe:2.3:a:becauseinter:bournal:1.3:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*