Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 05:09:03 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1444591659&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Ffiledesc%2Fsecunia-bccrypt.txt.html%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1444591659.1338181743.1338181743.1338181743.1%3B%2B__utmz%3D32867617.1338181743.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Bournal ccrypt Information Disclosure http://packetstormsecurity.org/files/86593/secunia-bccrypt.txt http://packetstormsecurity.org/files/86593/secunia-bccrypt.txt http://packetstormsecurity.org/files/86593/Bournal-ccrypt-Information-Disclosure.html Wed, 24 Feb 2010 00:33:21 GMT Secunia Research has discovered a security issue in Bournal, which can be exploited by malicious, local users to disclose sensitive information. The script uses e.g. the insecure "-K" command line parameter to pass the key to the ccrypt utilities, which can be exploited to obtain the key from the list of running processes. Note: This may not affect recent Linux versions, but is confirmed for FreeBSD 8.0. Other systems may also be affected. Version 1.4 is affected.