Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."
2010-02-25T00:30:00.453
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | becauseinter | bournal | ≤ 1.4 | Yes |
| Application | becauseinter | bournal | 0.1 | Yes |
| Application | becauseinter | bournal | 0.2 | Yes |
| Application | becauseinter | bournal | 0.3 | Yes |
| Application | becauseinter | bournal | 0.4 | Yes |
| Application | becauseinter | bournal | 0.4.5 | Yes |
| Application | becauseinter | bournal | 0.6 | Yes |
| Application | becauseinter | bournal | 0.7 | Yes |
| Application | becauseinter | bournal | 0.8 | Yes |
| Application | becauseinter | bournal | 0.9 | Yes |
| Application | becauseinter | bournal | 1.0 | Yes |
| Application | becauseinter | bournal | 1.1 | Yes |
| Application | becauseinter | bournal | 1.2 | Yes |
| Application | becauseinter | bournal | 1.3 | Yes |
| Operating System | freebsd | freebsd | 8.0 | No |