Starfish TrueSync Desktop Password Disclosure Vulnerability
BID:3231
Info
Starfish TrueSync Desktop Password Disclosure Vulnerability
| Bugtraq ID: | 3231 |
| Class: | Design Error |
| CVE: |
CVE-2001-1005 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 24 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Reported to Bugtraq by Valentin Butanescu <[email protected]> on August 24, 2001. |
| Vulnerable: |
Starfish Software TrueSync Desktop 2.0 |
| Not Vulnerable: | |
Discussion
Starfish TrueSync Desktop Password Disclosure Vulnerability
Starfish Software's TrueSync Desktop is a personal information manager (PIM) software for Windows commonly used with wireless and wireline devices.
The TrueSync Desktop software provides users the ability to set a password for protecting stored files. The software employs a trivial method of protecting passwords. User passwords are stored in the system registry. Further, no encryption is used to protect password data, the software simply obfuscates it by printing a concatenation of the ASCII decimal representation for each character used in a password.
Starfish Software's TrueSync Desktop is a personal information manager (PIM) software for Windows commonly used with wireless and wireline devices.
The TrueSync Desktop software provides users the ability to set a password for protecting stored files. The software employs a trivial method of protecting passwords. User passwords are stored in the system registry. Further, no encryption is used to protect password data, the software simply obfuscates it by printing a concatenation of the ASCII decimal representation for each character used in a password.
References
Starfish TrueSync Desktop Password Disclosure Vulnerability
References:
References:
- Starfish Software Homepage (Starfish Software)