PT-2003-1332 · Vandyke · Securefx+2

Knud Erik Højgaard

·

Published

2003-02-01

·

Updated

2016-10-18

·

CVE-2003-0047

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SecureCRT versions 3.4.7 and 4.0.2 SecureFX versions 2.0.4 and 2.1.2 Entunnel versions 1.0.2 and earlier
Description The issue concerns the failure of SSH2 clients to clear logon credentials from memory. This includes plaintext passwords, which could be stolen by attackers with access to memory.
Recommendations For SecureCRT versions 3.4.7 and 4.0.2, update to a version that properly clears logon credentials from memory. For SecureFX versions 2.0.4 and 2.1.2, update to a version that properly clears logon credentials from memory. For Entunnel versions 1.0.2 and earlier, update to a version that properly clears logon credentials from memory.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0047

Affected Products

Entunnel
Securecrt
Securefx