Counterpane Password Safe Data Buffer Recovery Vulnerability
Counterpane Password Safe is a freely available password storage program designed to
securely store usernames and passwords, assessable by one master password, or
"combination" to the safe.
A problem in Password Safe makes it possible for local users to gain access to clear text
usernames, and potentially passwords. When the program option to clear passwords from
the clipboard is enabled, Windows will copy the contents of the clipboard to a buffer prior
to minimizing the program.
This makes it possible for a local user to gain access to usernames, and potentially passwords.
bugtraq id
3337
class
Environment Error
cve
CVE-MAP-NOMATCH
remote
No
local
Yes
published
September 13, 2001
updated
September 13, 2001
vulnerable
Counterpane Password Safe 1.7.1
- Microsoft Windows 98se
- Microsoft Windows 98SP1
- Microsoft Windows 98
- Microsoft Windows 95b
- Microsoft Windows 95a
- Microsoft Windows 95
- Microsoft Windows NT 4.0SP7
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP6a
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP6
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP5
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP4
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP3
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP2
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0SP1
+ Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0
- Microsoft Windows 2000 SP3
+ Microsoft Windows 2000
- Microsoft Windows 2000 SP2
+ Microsoft Windows 2000
- Microsoft Windows 2000 SP1
+ Microsoft Windows 2000
- Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000
- Microsoft Windows 2000
- Microsoft Windows 2000 Server SP2
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Professional SP2
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000
- Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000
- Microsoft Windows 2000 Professional
+ Microsoft Windows 2000
- Microsoft Windows 2000 Datacenter Server SP2
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Datacenter Server SP1
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Advanced Server SP2
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000
- Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000