LOW · 2.1

CVE-2010-0119

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its argume...

Vulnerability Description

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
BecauseinterBournal<= 1.4
FreebsdFreebsd8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0119?

CVE-2010-0119 is a vulnerability with a CVSS score of 2.1 (LOW). Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its argume...

How severe is CVE-2010-0119?

CVE-2010-0119 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0119?

Check the references section above for vendor advisories and patch information. Affected products include: Becauseinter Bournal, Freebsd Freebsd.