iViZ Security
RESEARCH
Security Advisories

Security Advisories

IVIZ-08-008: LILO Security Model bypass exploiting wrong BIOS API usage

25-Aug-2008

The password checking routine of LILO fails to sanitize the BIOS keyboard buffer before AND after reading passwords.

View Details

IVIZ-08-007: DriveCryptor Security Model bypass exploiting wrong BIOS API usage

25-Aug-2008

The password checking routine of DiskCryptor fails to sanitize the BIOS keyboard buffer before AND after reading passwords.

View Details

IVIZ-08-006: DiskCryptor Security Model bypass exploiting wrong BIOS API usage

25-Aug-2008

The password checking routine of DiskCryptor fails to sanitize the BIOS keyboard buffer before AND after reading passwords.

View Details

IVIZ-08-005: Lenovo BIOS Plain Text Password Disclosure

25-Aug-2008

Like most BIOSes, Lenovo's firmware 7CETB5WW v2.05 (10/13/2006) can be used to ask a password to users at boot time to implement a pre-boot authentication. The password checking routine of this firmware fails to sanitize the BIOS keyboard buffer after reading user input, resulting in plaintext password leakage to local users.

View Details

<< Prev|Page 1|2|3|4|Next >>

Copyright © 2005-2009 iViZ Techno Solutions Pvt. Ltd. All rights reserved.