Vulnerabilities > CVE-2006-1378 - Unspecified vulnerability in Counterpane Password Safe 3.0

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
local
low complexity
counterpane

Summary

PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack. This vulnerability exists only in Windows OS environments before XP. For some reason it would not let me notate that in the "vulnerable software" section.

Vulnerable Configurations

Part Description Count
Application
Counterpane
1