CVE-2011-1500

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
13/04/2011
Last modified:
11/04/2025

Description

PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by reading this file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kevinmehall:pithos:0.3.7:*:*:*:*:*:*:*