PT-2001-2135 · Unknown · Passwordsafe
Publicado
2001-09-13
·
Atualizado
2017-12-20
·
CVE-2001-0984
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Password Safe version 1.7(1)
Description
The issue allows an attacker with access to the memory, such as an administrator, to read passwords that are left in cleartext when a user copies the password to the clipboard and minimizes Password Safe. This occurs when the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options are enabled.
Recommendations
For Password Safe version 1.7(1), consider disabling the clipboard copying feature or the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options as a temporary workaround until a patch is available. Alternatively, restrict access to the system memory to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Passwordsafe