CVE-2019-7306
published 2020-04-17CVE-2019-7306: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.62%
73.6th percentile
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | byobu | >= unspecified < 5.128-0ubuntu1 | 5.128-0ubuntu1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | byobu | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2rpx-jj49-wf29: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's
ghsa_unreviewed·2022-05-24
CVE-2019-7306 [MEDIUM] CWE-200 GHSA-2rpx-jj49-wf29: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
OSV
CVE-2019-7306: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's
osv·2020-04-17·CVSS 7.5
CVE-2019-7306 [HIGH] CVE-2019-7306: Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
Ubuntu
Byobu vulnerability
vendor_ubuntu·2022-01-18
CVE-2019-7306 Byobu vulnerability
Title: Byobu vulnerability
Summary: Byobu could be made to expose sensitive information.
Sander Bos discovered that Byobu incorrectly handled certain Apport data.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-7306: byobu - Byobu Apport hook may disclose sensitive information since it automatically uplo...
vendor_debian·2019·CVSS 4.3
CVE-2019-7306 [MEDIUM] CVE-2019-7306: byobu - Byobu Apport hook may disclose sensitive information since it automatically uplo...
Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-17
Published