Security Advisory |
|||||||||||||||||||||
VanDyke Software has released new versions of its client applications to eliminate a security issue in previous versions. The issue made login credentials transmitted by VanDyke secure clients vulnerable to discovery if an attacker were able to access memory or a memory dump on the local machine. |
|||||||||||||||||||||
Posted: January 29, 2003 Description iDEFENSE, a security analysis firm, has reported that VanDyke Software Inc.'s SecureCRT® does not properly scrub memory, allowing an attacker with access to memory or a memory dump to retrieve authentication information. An attacker can search memory or a memory dump on the local machine for login credentials. Passwords transmitted by SecureCRT can be found by searching for the string "ssh-connection". The login and password are stored in plain-text on the respective sides of this keyword. An attacker that is able to ascertain a target user's memory dump will be able to recover passwords for remote systems. This is of special concern in shared environments. If a user suspects that his or her login credentials have been compromised then he or she should immediately change them. This vulnerability exists in the following versions of VanDyke Software client applications:
Earlier versions of these client applications are vulnerable as well. VanDyke encourages all users whose licenses were purchased prior to June 1, 2000 to consider upgrading to the current version(s) of their licensed applications.
|
VanDyke Software uses cookies to give you the best online experience. Before continuing to use this site, please confirm that you agree to our use of cookies. Please see our Cookie Usage for details.
Here you can control cookies using the checkboxes below. Some cookies are essential for the use of our website and cannot be disabled. Others provide a convenience to the user and, if disabled, may reduce the ease of use of our site. Finally, some cookies provide anonymous analytic tracking data that help us provide the user with a richer browsing experience. You can elect to disable these cookies as well.