CVE-2019-7306

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
Configurations

Configuration 1 (hide)

cpe:2.3:a:byobu:byobu:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

History

21 Nov 2024, 04:47

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 4.3
References () https://bugs.launchpad.net/ubuntu/+source/byobu/+bug/1827202 - Exploit, Third Party Advisory () https://bugs.launchpad.net/ubuntu/+source/byobu/+bug/1827202 - Exploit, Third Party Advisory
References () https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7306 - Third Party Advisory () https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7306 - Third Party Advisory

Information

Published : 2020-04-17 02:15

Updated : 2024-11-21 04:47


NVD link : CVE-2019-7306

Mitre link : CVE-2019-7306

CVE.ORG link : CVE-2019-7306


JSON object : View

Products Affected

canonical

  • ubuntu_linux

byobu

  • byobu
CWE
CWE-552

Files or Directories Accessible to External Parties