SB2015052003 - Information disclosure in Piriform CCleaner
Published: May 20, 2015 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2015-3999)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.
Remediation
Install update from vendor's website.