Bugtraq mailing list archives

Re: ActivCard password cache memory leakage


From: Massimo Cereda <massimo.cereda () cgweb it>
Date: 15 Apr 2003 14:59:04 -0000

In-Reply-To: <9969CF31A0D6D411BC4B00508BB38E84031F4D94@BAIMSG4>

The problem found relates to accessing static passwords stored (for
performance) in a memory cache by ActivCard Gold. ActivCard recognizes the
seriousness of this problem, and will fix it in the next version of the
product - ActivCard is currently working on a mechanism that will prevent 
a
memory dump to access any kind of personal data. 

The new Gold 2.3 was relased last week, is still vulnerable?

Massimo


Current thread: