what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

ISL Light Desktop 3.5.4 Information Disclosure

ISL Light Desktop 3.5.4 Information Disclosure
Posted Dec 3, 2013
Authored by Juan Francisco

ISL Light - Desktop version 3.5.4 suffers from an information disclosure vulnerability. In cases where a person is hosting a sharing session and allows a remote user to see what is happening on the local PC, it has been discovered that if you locally copy something like a hidden password to the local clipboard, then the remote user will be able to directly paste it in clear text into a notepad or other form of document, effectively gaining access to the password. It is not possible to lock this functionality.

tags | exploit, remote, local, info disclosure
advisories | CVE-2013-6237
SHA-256 | 9d0c82286b45ad8906e8301b87342b3bf556f6afcccf8574e717abd46e0af646

ISL Light Desktop 3.5.4 Information Disclosure

Change Mirror Download
CVE-2013-6237:ISL Light - Desktop 3.5.4, Clipboard security issue


In cases where a person is hosting a sharing session and allows a remote
user to see what is happening on the local PC, it’s been discovered that if
you locally copy something like a hidden password to the local clipboard,
then the remote user will be able to directly paste it in clear text into a
notepad or other form of document, effectively gaining access to the
password. Not possible to lock this functionality.


Example,
1. You start ISLonline Console session
2. External consultant joins session using ISLonline Support
3. You copy a password into your computers copy buffer
a. E.g. from KeePass Password Manager
4. Security issue: External consultants can now paste your password
into e.g. his own Notepad as see it in clear text
a. Password is revealed
b. The other problem is that password remain in his copy buffer
after session ends
c. E.g. KeePass’s auto clean copy buffer feature does not
prevent problem


Vendor: http://www.islonline.com/

Vendor issue code: ISLLIGHT-557,
http://www.islonline.com/help/isl-releases-info/any/manual/?2013-11-29-rel-info-isl-light-desktop-plugin-1-4-7-win.htm

Affected product: ISL light 3.5.4 compiled on Sep 26 2013 revision 30035

Solved: ISL Light Desktop plugin for Windows 1.4.7 (2013-11-29)

Credit: This issue was reported by Juan Francisco Bolivar
es.linkedin.com/in/jfbolivar/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6237

J. Francisco Bolivar
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close