Whisper 32 1.16, and possibly earlier versions, stores passwords in plaintext in memory, which allows local users to obtain the password using a debugger or another mechanism to read process memory.
Link | Tags |
---|---|
http://securitytracker.com/id?1014730 | vdb entry |
http://antilamo.skifstone.com/vuln/whisper32.txt | vendor advisory |
http://marc.info/?l=bugtraq&m=112438834310990&w=2 | mailing list |
http://www.securityfocus.com/bid/14600 | vdb entry |