Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=102130733815285&w=2 | mailing list |
http://www.securityfocus.com/bid/4730 | vdb entry |
http://gaim.sourceforge.net/ChangeLog | vendor advisory |
http://archives.neohapsis.com/archives/vuln-dev/2002-q2/0584.html | mailing list |
http://www.iss.net/security_center/static/9061.php | vdb entry |