ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1307 | patch vendor advisory vdb entry third party advisory broken link |
http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html | mailing list patch vendor advisory exploit broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/4607 | vdb entry third party advisory |