mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mysql-gui-tools | Oracle | * | 5.0r14+opensuse-2.3 (excluding) |
Mysql-gui-tools | Ubuntu | hardy | * |
Mysql-gui-tools | Ubuntu | lucid | * |
Mysql-gui-tools | Ubuntu | natty | * |
Mysql-gui-tools | Ubuntu | oneiric | * |