login_screen.tcl in aMSN (aka Alvaros Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Amsn | Amsn | * | 0.97 (including) |
Amsn | Amsn | 0.83 (including) | 0.83 (including) |
Amsn | Amsn | 0.90 (including) | 0.90 (including) |
Amsn | Amsn | 0.91 (including) | 0.91 (including) |
Amsn | Amsn | 0.92 (including) | 0.92 (including) |
Amsn | Amsn | 0.93 (including) | 0.93 (including) |
Amsn | Amsn | 0.94 (including) | 0.94 (including) |
Amsn | Amsn | 0.95 (including) | 0.95 (including) |
Amsn | Amsn | 0.96 (including) | 0.96 (including) |
Amsn | Ubuntu | dapper | * |
Amsn | Ubuntu | hardy | * |
Amsn | Ubuntu | upstream | * |