Anonymous Login

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0000061SKGB-internneues-kennwortpublic2006-03-06 00:27
Reporteraj 
Assigned Toaj 
PrioritynormalSeverityminorReproducibilityalways
StatusresolvedResolutionfixed 
Projectionminor fixETAnone 
PlatformApple PowerBook G4OSMac OS XOS Version10.4.3
Product Version1.0.1Product Build 
Target VersionFixed in Version1.1 
Summary0000061: pwtickets always contains user/password combo in clear
DescriptionThe user/password combination is spawned immediately after requesting the ticket and stored in the pwtickets file. If the ticket is never claimed, the user/password combo could be abused by an attacker with access to the pwticket. The user/password combo should only be added to the file after the user received it to minimize the risk period.
TagsNo tags attached.
Attached Files

-Relationships
child of 0000043resolved (1.1) 
+Relationships

-Notes
There are no notes attached to this issue.
+Notes