CVE-2006-6680

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/12/2006
Last modified:
05/09/2008

Description

Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:chetcpasswd:chetcpasswd:2.2.1:*:*:*:*:*:*:*