PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not be necessary as there is no evidence yet that these screen intercepts are actually transported away from the local host." NOTE: it is unclear whether there are any common use cases in which apinotifypath is controlled by an attacker
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T20:33:41.321Z
Reserved: 2021-02-08T00:00:00
Link: CVE-2021-26917
No data.
Status : Modified
Published: 2021-02-08T23:15:11.973
Modified: 2024-11-21T05:57:02.290
Link: CVE-2021-26917
No data.
OpenCVE Enrichment
No data.
Weaknesses