CVE-2006-3785
Summary
| CVE | CVE-2006-3785 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-24 12:19:00 UTC |
| Updated | 2018-10-17 21:30:00 UTC |
| Description | Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft Asterwin. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Pcanywhere | 12.5 | All | All | All |
| Application | Symantec | Pcanywhere | 12.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CXSecurity - IDS | SREASON | securityreason.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Digital Bullets » Archive » PcAnywhere > 12 - Local Privilege Escalation | MISC | www.digitalbullets.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.