Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/9021.php | patch vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-05/0035.html | patch vendor advisory mailing list |
http://www.securityfocus.com/bid/4681 | patch vdb entry |