IBM Concert Software
1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.
Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Concert | Ibm | 1.0.0 (including) | 2.1.0 (excluding) |