Dreameesoft Password Master Local Authentication Bypass Vulnerability
BID:19983
Info
Dreameesoft Password Master Local Authentication Bypass Vulnerability
| Bugtraq ID: | 19983 |
| Class: | Design Error |
| CVE: |
CVE-2006-7163 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Jonathan Read is credited with the discovery of this issue. |
| Vulnerable: |
Dreameesoft Password Master 1.0 |
| Not Vulnerable: |
Dreameesoft Password Master 3.5 |
Discussion
Dreameesoft Password Master Local Authentication Bypass Vulnerability
Dreameesoft Password Master is prone to an authentication-bypass vulnerability due to a design error.
Setting a master password may lead to a false sense of security, since users may expect that this results in an encrypted database. This vulnerability implies that this is not the case, because an attacker may be able to remove the master password.
Successful exploits may allow an attacker with local access to a mobile device running the vulnerable software to bypass the application's authentication methods and retrieve sensitive information.
Version 1.0 is vulnerable to this issue; other versions may also be affected.
Dreameesoft Password Master is prone to an authentication-bypass vulnerability due to a design error.
Setting a master password may lead to a false sense of security, since users may expect that this results in an encrypted database. This vulnerability implies that this is not the case, because an attacker may be able to remove the master password.
Successful exploits may allow an attacker with local access to a mobile device running the vulnerable software to bypass the application's authentication methods and retrieve sensitive information.
Version 1.0 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Dreameesoft Password Master Local Authentication Bypass Vulnerability
To exploit this issue, an attacker must have physical access to a vulnerable device.
To exploit this issue, an attacker must have physical access to a vulnerable device.
Solution / Fix
Dreameesoft Password Master Local Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Reportedly, version 3.5 is not affected by this vulnerability; Symantec has not confirmed this.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Reportedly, version 3.5 is not affected by this vulnerability; Symantec has not confirmed this.
References
Dreameesoft Password Master Local Authentication Bypass Vulnerability
References:
References:
- Dreameesoft Homepage (Dreameesoft)