PT-2006-4541 · Unknown · Passwordsafe

J.R. Wikes

·

Published

2006-07-28

·

Updated

2018-10-18

·

CVE-2006-3675

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Password Safe versions 2.11 through 3.0BETA1
Description The issue concerns the password database locking mechanism. When specific dialogue windows are open, the configuration settings for locking the database are not respected. This could allow attackers with physical access to obtain the database contents.
Recommendations For versions 2.11 through 3.0BETA1, consider implementing additional access controls to the password database when dialogue windows are open, such as manually locking the database or restricting physical access to the device.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3675

Affected Products

Passwordsafe