VYPR
Moderate severityNVD Advisory· Published Oct 4, 2007· Updated Apr 23, 2026

CVE-2007-5201

CVE-2007-5201

Description

The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
duplicityPyPI
< 0.4.90.4.9

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.