CVE-2016-7553
Description
The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.
References
Third Party Advisory
PatchVendor Advisory
Patch
Third Party AdvisoryVDB Entry
Mailing ListPatch
Mailing ListPatch
CvssV3 impact
BaseSeverity | LOW |
ConfidentialityImpact | LOW |
AttackComplexity | LOW |
Scope | UNCHANGED |
AttackVector | LOCAL |
AvailabilityImpact | NONE |
IntegrityImpact | NONE |
PrivilegesRequired | LOW |
BaseScore | 3.3 |
VectorString | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Version | 3.0 |
UserInteraction | NONE |
CvssV2 impact
Version | 2.0 |
VectorString | AV:L/AC:L/Au:N/C:P/I:N/A:N |
AccessVector | LOCAL |
AccessComplexity | LOW |
Authentication | NONE |
ConfidentialityImpact | PARTIAL |
IntegrityImpact | NONE |
AvailabilityImpact | NONE |
BaseScore | 2.0999999046325684 |