PT-2006-4541 · Unknown · Passwordsafe
J.R. Wikes
·
Published
2006-07-28
·
Updated
2018-10-18
·
CVE-2006-3675
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Password Safe versions 2.11 through 3.0BETA1
Description
The issue concerns the password database locking mechanism. When specific dialogue windows are open, the configuration settings for locking the database are not respected. This could allow attackers with physical access to obtain the database contents.
Recommendations
For versions 2.11 through 3.0BETA1, consider implementing additional access controls to the password database when dialogue windows are open, such as manually locking the database or restricting physical access to the device.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Passwordsafe