Starfish TrueSync Desktop Password Disclosure Vulnerability

Starfish Software's TrueSync Desktop is a personal information manager (PIM) software for Windows commonly used with wireless and wireline devices.

The TrueSync Desktop software provides users the ability to set a password for protecting stored files. The software employs a trivial method of protecting passwords. User passwords are stored in the system registry. Further, no encryption is used to protect password data, the software simply obfuscates it by printing a concatenation of the ASCII decimal representation for each character used in a password.


 

Privacy Statement
Copyright 2010, SecurityFocus