mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-4177 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4177 | issue tracking third party advisory |
https://access.redhat.com/security/cve/cve-2010-4177 | third party advisory broken link |
http://www.securityfocus.com/bid/97959 | vdb entry third party advisory |
https://www.openwall.com/lists/oss-security/2010/11/16/6 | third party advisory mailing list |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605542 | third party advisory mailing list |