« Volver al listado

CVE-2010-0119

Estado: ModificadaBaja (2.1)—

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0119",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT-CNA@flexerasoftware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-02-25T00:30:00.453",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/38723",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/38814",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2010-7/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/509688/100/0/threaded",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/38352",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38723",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38814",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2010-7/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/509688/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/38352",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to \"echoing.\""
    },
    {
      "lang": "es",
      "value": "Bournal anterior a v1.4.1 sobre FreeBSD v8.0, cuando se usa la opción -K, coloca una clave ccrypt en la línea de comandos que permite a usuarios locales obtener información sensible listando el proceso y sus argumentos. Relacionado con \"echoing\"."
    }
  ],
  "lastModified": "2026-06-16T23:15:30.900",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D468CAD-3063-46EB-AE99-F7400BB7B7C5",
              "versionEndIncluding": "1.4"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1709541-EA26-4527-8B4D-331F4085E7E7"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C9498E5-376E-4A41-B399-83285B88925E"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1F136FE-A8AD-4CF6-8689-110E375E9ADC"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB21BB24-819A-4929-8AAC-E304F8EF2657"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69FDF8DB-E4E1-46E0-ACC4-9D57CE0C001F"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CE6BE57-15E3-48E2-871E-63D26E5A9B43"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA9ADE86-B2D7-4F90-9FE2-E944E331DEF5"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "095A3649-480E-49D7-9B00-0BBB811A7223"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDD2EA99-A3F1-46AB-954D-67470EBB8AAB"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FD3F8DD-A9D1-4679-ABF9-0A314578CB9C"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "315AFC7C-956F-49A1-9FDE-490E46FCC53F"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E40B531F-2707-4A4D-A6F3-52A72514E1E7"
            },
            {
              "criteria": "cpe:2.3:a:becauseinter:bournal:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11D63362-6AD3-49F6-9980-D70159F5E8CE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:8.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3CF1F9EF-01AF-4708-AE02-765360AF3D66"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}