VulnerabilityModified
CVE-2008-2517
The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the process.
LOW 2.1EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the process.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sarab/sarab
- Source
- cve@mitre.org
References
- http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?r1=34&r2=36Exploit
- http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?view=log
- http://secunia.com/advisories/30394Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=601603&group_id=91804
- http://www.securityfocus.com/bid/29364
- http://www.vupen.com/english/advisories/2008/1659/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42621
- http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?r1=34&r2=36Exploit
- http://sarab.svn.sourceforge.net/viewvc/sarab/sarab/sarab.sh?view=log
- http://secunia.com/advisories/30394Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=601603&group_id=91804
- http://www.securityfocus.com/bid/29364
- http://www.vupen.com/english/advisories/2008/1659/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42621
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.