Email us! Subscribe to Liquidmatrix!

CREDANT Fails To Remove Creds From Memory

Specifically, the “Mobile Guardian Shield” product. Here is the vulnerability note on US-CERT.

CREDANT Mobile Guardian (CMG) Shield is a component of Mobile Guardian Enterprise Edition. CMG Shield provides policy-based encryption of specified files. CMG Shield fails to properly clear credentials out of system memory. The default configuration for CMG Shield does not encrypt the Windows pagefile, which means that the credentials may be written to disk. Please see the CREDANT vendor statement below in this vulnerability note for more details.

This is unfortunate for Credant. There is a patch available for Credant customers.

Article Link

Tags: , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • ARCserver Tape Engine Memory Corruption
  • Resurrect Deleted Photos From Camera’s Memory Card
  • Ophcrack Live CD Password Cracker
  • Sober Second Thought On IE7
  • Microsoft Excel Multiple Vulnerabilities
  • Leave a Comment