Symantec pcAnywhere 11.5.x and 12.0.x retains unencrypted login credentials for the most recent login within process memory, which allows local administrators to obtain the credentials by reading process memory, a different vulnerability than CVE-2006-3785.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/34203 | vdb entry |
http://www.vupen.com/english/advisories/2007/1753 | vdb entry |
http://osvdb.org/41982 | vdb entry |
http://securityresponse.symantec.com/avcenter/security/Content/2007.05.09b.html | patch |
http://securitytracker.com/id?1018032 | patch vdb entry |
http://www.securityfocus.com/bid/23875 | vdb entry |