RSS   Vulnerabilities for 'Undercover'   RSS

2006-02-10
 
CVE-2006-0641

CWE-Other
 

 
Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information to an unintended remote destination.

 
 
CVE-2006-0640

CWE-Other
 

 
Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.

 


Copyright 2024, cxsecurity.com

 

Back to Top