CERTA-2006-AVI-309
Vulnerability from certfr_avis
Password Safe est un logiciel libre permettant de gérer un ensemble de mots de passe. Une des fonctions de sécurité de cette application permet de vérrouiller la base de données des mots de passe stockés, par exemple à l'issue d'une certaine période d'inactivité. Cependant, ce vérouillage de la base de données comprend une vulnérabilité qui empêche sa réalisation lorsque certaines fenêtres sont ouvertes.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
NoneImpacted products
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Password Safe 2.11",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
},
{
"description": "Password Safe 3.0 BETA1",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
},
{
"description": "Password Safe 2.16",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [],
"initial_release_date": "2006-07-25T00:00:00",
"last_revision_date": "2006-07-25T00:00:00",
"links": [
{
"title": "Bulletin de s\u00e9curit\u00e9 :",
"url": "http://sourceforge.net/projects/passwordsafe/"
}
],
"reference": "CERTA-2006-AVI-309",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2006-07-25T00:00:00.000000"
}
],
"risks": [
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
}
],
"summary": "Password Safe est un logiciel libre permettant de g\u00e9rer un ensemble de\nmots de passe. Une des fonctions de s\u00e9curit\u00e9 de cette application permet\nde v\u00e9rrouiller la base de donn\u00e9es des mots de passe stock\u00e9s, par exemple\n\u00e0 l\u0027issue d\u0027une certaine p\u00e9riode d\u0027inactivit\u00e9. Cependant, ce v\u00e9rouillage\nde la base de donn\u00e9es comprend une vuln\u00e9rabilit\u00e9 qui emp\u00eache sa\nr\u00e9alisation lorsque certaines fen\u00eatres sont ouvertes.\n",
"title": "Vuln\u00e9rabilit\u00e9 dans Password safe",
"vendor_advisories": []
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…