OSVDB ID: 5887

Title: Microsoft Access 97 Cleartext Password Storage

Info

Disclosure

Jun 23, 1998

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Microsoft Access contains a flaw that may lead to an unauthorized password exposure. It is possible to gain access to plaintext passwords when a Access database file (.mdb) is leaked, which may lead to a loss of confidentiality and integrity.

Classification

Location: Local Access Required
Attack Type: Cryptographic, Information Disclosure
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Use a third party encryption system, such as PGP.

Products

Microsoft Corporation

Access

97

References

Credit

  • Adam Shostack - adamBrand New Doo Doohomeport.org -


Direct URL: http://osvdb.org/36218