The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2014/07/07/23 | mailing list exploit third party advisory |
http://www.openwall.com/lists/oss-security/2014/07/17/5 | mailing list exploit third party advisory |
https://github.com/panthomakos/lynx/issues/3 | third party advisory |
http://www.vapid.dhs.org/advisories/lynx-0.2.0.html | third party advisory exploit |