xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Counterpane Password Safe数据缓冲可恢复漏洞


发布时间:2001-09-17
更新时间:2001-09-17
严重程度:
威胁程度:口令恢复
错误类型:配置错误
利用方式:服务器模式

受影响系统
Counterpane Password Safe 1.7.1
   - Microsoft Windows 98se
   - Microsoft Windows 98SP1
   - Microsoft Windows 98
   - Microsoft Windows 95b
   - Microsoft Windows 95a
   - Microsoft Windows 95
   - Microsoft Windows NT 4.0SP7
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP6a
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP6
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP5
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP4
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP3
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP2
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP1
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0
   - Microsoft Windows 2000 SP3
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000 Datacenter Server
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - Microsoft Windows 2000 Server SP2
      + Microsoft Windows 2000 Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Server SP1
      + Microsoft Windows 2000 Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Server
      + Microsoft Windows 2000
   - Microsoft Windows 2000 Professional SP2
      + Microsoft Windows 2000 Professional
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Professional SP1
      + Microsoft Windows 2000 Professional
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Professional
      + Microsoft Windows 2000
   - Microsoft Windows 2000 Datacenter Server SP2
      + Microsoft Windows 2000 Datacenter Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Datacenter Server SP1
      + Microsoft Windows 2000 Datacenter Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Advanced Server SP2
      + Microsoft Windows 2000 Advanced Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Advanced Server SP1
      + Microsoft Windows 2000 Advanced Server
         + Microsoft Windows 2000
   - Microsoft Windows 2000 Advanced Server
      + Microsoft Windows 2000
详细描述
Counterpane Password Safe是免费的密码存储程序,实际用来安全的存储用户名和密码。

其中在Password Safe存在漏洞可以导致本地用户获得明文用户名和密码,当程序从剪贴版上清除密码选项激活以后,WINDOWS会拷贝缓冲内容到剪贴般,这样就有可能本地用户获得用户名或者密码等信息。

测试代码
尚无

解决方案
尚无

相关信息