GNotebook Discloses Passwords to Local Users
|
|
SecurityTracker Alert ID: 1017286
|
|
SecurityTracker URL: http://securitytracker.com/id?1017286
|
|
CVE Reference: CVE-2006-6182
(Links to External Site)
|
Updated: May 27 2008
|
Original Entry Date: Nov 27 2006
|
Impact: Disclosure of authentication information
|
Vendor Confirmed: Yes
|
Version(s): 0.7.0.1
|
Description: Richard Reed reported a vulnerability in the GNotebook plugin for Google Desktop. A local user can obtain the Gmail password.
The GNotebook plugin records the Gmail password in a log file in the temporary directory.
|
Impact: A local user can obtain a target user's Gmail password.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: desktop.google.com/plugins/i/gnotebooks.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: "Richard Reed" <ammon.ra.eg@gmail.com>
|
Message History:
None.
|
Source Message Contents
|
Date: Sun, 26 Nov 2006 22:19:33 -0600
From: "Richard Reed" <ammon.ra.eg@gmail.com>
Subject: Plaintext password storage for google destkop Gnotebook plugin
|
It seems that the google desktop plugin for "Gnotebook" stores a log
file in *:\temp\ named Gnotebook.txt in this logfile it stores gmail
password in plain text.
***************
2:15:50 AM.364 - Trace: test
2:15:50 AM.384 - Trace: doNextLogon
2:16:18 AM.154 - Trace: user_email.length == 0
2:16:34 AM.417 - Trace: ---- view_onOptionChanged ----
2:16:34 AM.417 - Trace: users
2:16:34 AM.417 - Trace:
Here: note ***************
UM([UL('ammon.ra.eg@gmail.com@gmail.com',***************',5,1)]);
2:16:34 AM.417 - Trace: test
2:16:34 AM.427 - Trace: doNextLogon
2:16:34 AM.427 - Trace: _authenticate
Here: note ***************
url: https://www.google.com/accounts/ServiceLoginAuth?continue=http://google.com/notebook&service =notebook&nui=1&Email=ammon.ra.eg@gmail.com@gmail.com&Passwd=***************&submit=n ull&PersistentCookie=yes&rmShown=1
2:16:34 AM.447 - Trace: user_email.length == 0
2:16:35 AM.138 - Trace: [ammon.ra.eg@gmail.com@gmail.com]
headers:Content-Type: text/html; charset=UTF-8
Cache-control: private
Transfer-Encoding: chunked
Content-Encoding: gzip
Date: Sun, 22 Oct 2006 07:16:28 GMT
Server: GFE/1.3
|
|