VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=122331139823057&w=2 | mailing list |
http://secunia.com/advisories/32179 | third party advisory |
http://www.vupen.com/english/advisories/2008/2740 | vdb entry |
http://www.securitytracker.com/id?1020992 | vdb entry |
http://secunia.com/advisories/32180 | third party advisory vendor advisory |
http://www.vmware.com/security/advisories/VMSA-2008-0016.html | patch |
http://www.securityfocus.com/bid/31569 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45664 | vdb entry |
http://www.securityfocus.com/archive/1/497041/100/0/threaded | mailing list |