SafeWord RemoteAccess Local Information Disclosure Vulnerability
BID:20509
Info
SafeWord RemoteAccess Local Information Disclosure Vulnerability
| Bugtraq ID: | 20509 |
| Class: | Design Error |
| CVE: |
CVE-2006-5303 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 13 2006 12:00AM |
| Updated: | Mar 19 2015 08:14AM |
| Credit: | nnposter is credited with the discovery of this vulnerability. |
| Vulnerable: |
Secure Computing SafeWord RemoteAccess 2.1 |
| Not Vulnerable: | |
Discussion
SafeWord RemoteAccess Local Information Disclosure Vulnerability
SafeWord RemoteAccess is prone to an information-disclosure vulnerability because it stores sensitive data with insecure permissions.
A malicious local user could leverage this issue to obtain sensitive information that could aid in attacks against the system.
Version 2.1 is vulnerable; other versions may also be affected.
SafeWord RemoteAccess is prone to an information-disclosure vulnerability because it stores sensitive data with insecure permissions.
A malicious local user could leverage this issue to obtain sensitive information that could aid in attacks against the system.
Version 2.1 is vulnerable; other versions may also be affected.
Exploit / POC
SafeWord RemoteAccess Local Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SafeWord RemoteAccess Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SafeWord RemoteAccess Local Information Disclosure Vulnerability
References:
References:
- SafeWord RemoteAccess Homepage (Secure Computing)