CVE Vulnerabilities

CVE-2006-2443

Published: May 18, 2006 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.

Affected Software

Name Vendor Start Version End Version
Knowledgetree Knowledgetree 2.0.7 (including) 2.0.7 (including)
Knowledgetree Ubuntu dapper *
Knowledgetree Ubuntu edgy *
Knowledgetree Ubuntu feisty *
Knowledgetree Ubuntu gutsy *

References