LineControl Java Client Local Password Disclosure Vulnerability
BID:14830
Info
LineControl Java Client Local Password Disclosure Vulnerability
| Bugtraq ID: | 14830 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 14 2005 12:00AM |
| Updated: | Sep 14 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
LineControl Java Client 0.8 |
| Not Vulnerable: |
LineControl Java Client 0.8.1 |
Discussion
LineControl Java Client Local Password Disclosure Vulnerability
LineControl Java Client is prone to a password disclosure vulnerability. This is due to a design error in the application.
LineControl Java Client version 0.8.0 is is vulnerable to this issue, however, other versions may be affected as well.
LineControl Java Client is prone to a password disclosure vulnerability. This is due to a design error in the application.
LineControl Java Client version 0.8.0 is is vulnerable to this issue, however, other versions may be affected as well.
Exploit / POC
LineControl Java Client Local Password Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
LineControl Java Client Local Password Disclosure Vulnerability
Solution:
The vendor has released version 0.8.1 to address this issue.
LineControl Java Client 0.8
Solution:
The vendor has released version 0.8.1 to address this issue.
LineControl Java Client 0.8
-
LineControl jlc-0.8.1.tar.gz
http://prdownloads.sourceforge.net/linecontrol/jlc-0.8.1.tar.gz
References
LineControl Java Client Local Password Disclosure Vulnerability
References:
References:
- LineControl Release Notes for version 0.8.1 (LineControl)
- LineControl Web Site (LineControl)