tsclient stores user/password as clear text
Bug #296682 reported by
clovepower
This bug affects 5 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tsclient |
Fix Committed
|
Critical
|
Unassigned | ||
tsclient (Ubuntu) |
Won't Fix
|
Wishlist
|
Unassigned | ||
Hardy |
Won't Fix
|
Wishlist
|
Unassigned | ||
Lucid |
Won't Fix
|
Wishlist
|
Unassigned | ||
Maverick |
Won't Fix
|
Wishlist
|
Unassigned | ||
Natty |
Won't Fix
|
Wishlist
|
Unassigned | ||
Oneiric |
Won't Fix
|
Wishlist
|
Unassigned |
Bug Description
Binary package hint: tsclient
tsclient 0.150-1ubuntu1
Ubuntu 8.04.1 AMD64
If you save tsclient connection parameters as RDP file, all data is stored as plain text, including user name and password to connect to the remote server.
User names and passwords should be stored in user keyring and not made visible.
client hostname:s:
xxxxxxxx
full address:s:xxxxxxx
password:b:xxxxxxxx
username:s:xxxxxxxx
Changed in tsclient (Ubuntu): | |
importance: | Undecided → Wishlist |
Changed in tsclient: | |
status: | New → Fix Committed |
importance: | Undecided → High |
importance: | High → Critical |
Changed in tsclient (Ubuntu): | |
status: | Confirmed → Triaged |
To post a comment you must log in.
Also, the very same data is stored under /home/< user>/. tsclient folder in last.tsc and mru.tsc files.
So, credentials are stored in clear text even if user is not explicitly saving an RDP file.