PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a users home directory, which allows local users to obtain Pandora credentials by reading this file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pithos | Kevinmehall | 0.3.7 (including) | 0.3.7 (including) |
Pithos | Ubuntu | upstream | * |