AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
References
Configurations
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=104386492422014&w=2 - | |
References | () http://www.celestialsoftware.net/telnet/beta_software.html - Vendor Advisory | |
References | () http://www.idefense.com/advisory/01.28.03.txt - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/7686 - | |
References | () http://www.securityfocus.com/bid/6725 - | |
References | () http://www.securitytracker.com/id?1006013 - |
Information
Published : 2003-02-19 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2003-0046
Mitre link : CVE-2003-0046
CVE.ORG link : CVE-2003-0046
JSON object : View
Products Affected
celestial_software
- absolutetelnet
CWE