Starfish TrueSync Desktop Failure to Protect Data Vulnerability

Starfish Software's TrueSync Desktop is a personal information manager (PIM) software for Windows commonly used with wireless and wireline devices.

The TrueSync Desktop software provides users the ability to set a password for protecting stored files. Aside from employing a trivial method of storing user passwords (see BID 3231), the software also does not encrypt protected data files in any way.

An attacker can easily view the files through some other application. This may lead to the disclosure of sensitive information.


Privacy Statement
Copyright 2010, SecurityFocus