Cocktail exposure of administrator password

Secunia has reported a security issue in Cocktail, which can be exploited by malicious, local users to disclose sensitive information. The problem is that the administrator password is insecurely passed to the sudo process via the command line and may be exposed to other users. The security issue has been reported in version 3.5.4. Prior versions may also be affected. All users are encouraged to upgrade to version 3.6.


About this entry