IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
BID:60536
Info
IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
| Bugtraq ID: | 60536 |
| Class: | Design Error |
| CVE: |
CVE-2013-0534 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2013 12:00AM |
| Updated: | Mar 19 2015 09:24AM |
| Credit: | Thaddeus Bogner |
| Vulnerable: |
IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.5 |
| Not Vulnerable: | |
Discussion
IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
IBM Sametime is prone to a local information-disclosure vulnerability because it fails to zero the plaintext password within the memory.
Attackers with access to memory on the affected user's system can exploit this issue to obtain passwords in plain text; this may aid in launching further attacks.
IBM Sametime is prone to a local information-disclosure vulnerability because it fails to zero the plaintext password within the memory.
Attackers with access to memory on the affected user's system can exploit this issue to obtain passwords in plain text; this may aid in launching further attacks.
Exploit / POC
IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
Attackers can exploit this issue by viewing memory of the affected system with readily available utilities.
Attackers can exploit this issue by viewing memory of the affected system with readily available utilities.
Solution / Fix
IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability
References:
References:
- IBM Homepage (IBM)