CVE-2012-0843
published 2019-11-19CVE-2012-0843: uzbl: Information disclosure via world-readable cookies storage file
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.43%
35.3th percentile
uzbl: Information disclosure via world-readable cookies storage file
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| uzbl | uzbl | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0843 uzbl: world-readable cookie file
bugzilla·2012-02-11·CVSS 5.5
CVE-2012-0843 [MEDIUM] CVE-2012-0843 uzbl: world-readable cookie file
CVE-2012-0843 uzbl: world-readable cookie file
A Debian bug report [1] indicated that uzbl would create the cookies storage
file with world readable permissions. This could allow other local users to
steal cookies if the user had non-default permissions on their home directory
(by default, home directories are mode 0700 but may be 0755 in some cases, like
for Apache user directories).
ls -ld ~/.local/{,share/{,uzbl/{,cookies.txt}}}
drwxr-xr-x 3 user users 4096 Feb 9 23:29 /home/user/.local/
drwxr-xr-x 4 user users 4096 Feb 9 23:29 /home/user/.local/share/
drwxr-xr-x 2 user users 4096 Feb 9 23:29 /home/user/.local/share/uzbl/
-rw-rw-rw- 1 user users 732 Feb 9 23:29 /home/user/.local/share/uzbl/cookies.txt
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659379
Discussion:
Created u
Bugzilla
CVE-2012-0843 uzbl: world-readable cookie file [fedora-all]
bugzilla·2012-02-11·CVSS 5.5
CVE-2012-0843 [MEDIUM] CVE-2012-0843 uzbl: world-readable cookie file [fedora-all]
CVE-2012-0843 uzbl: world-readable cookie file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=789645
Pl
http://www.openwall.com/lists/oss-security/2012/02/11/3https://access.redhat.com/security/cve/cve-2012-0843https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0843https://security-tracker.debian.org/tracker/CVE-2012-0843https://www.securityfocus.com/bid/52268http://www.openwall.com/lists/oss-security/2012/02/11/3https://access.redhat.com/security/cve/cve-2012-0843https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0843https://security-tracker.debian.org/tracker/CVE-2012-0843https://www.securityfocus.com/bid/52268
2019-11-19
Published