A vulnerability has been discovered in SnortCenter v0.9.5. SnortCenter creates temporary sensor configuration files which are 'world' accessible. The temporary sensor configuration files created by SnortCenter may contain usernames and passwords for alert database servers. Information disclosed by accessing this file may aid a malicious user in launching attacks against alert database servers. The ability to modify sensitive information contained within these files may result in the corruption of typical SnortCenter functionality.
A vulnerability has been discovered in SnortCenter v0.9.5. SnortCenter creates temporary sensor configuration files which are 'world' accessible. The temporary sensor configuration files created by SnortCenter may contain usernames and passwords for alert database servers. Information disclosed by accessing this file may aid a malicious user in launching attacks against alert database servers. The ability to modify sensitive information contained within these files may result in the corruption of typical SnortCenter functionality.