PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/7696 | vdb entry vendor advisory |
http://marc.info/?l=bugtraq&m=105405691423389&w=2 | mailing list |
http://www.iss.net/security_center/static/12083.php | vdb entry vendor advisory |