View Issue Details

IDProjectCategoryView StatusLast Update
0005122JEDI VCL00 JVCL Componentspublic2011-06-10 16:09
ReporterdeboseAssigned Toobones 
PrioritynormalSeveritytweakReproducibilityalways
Status resolvedResolutionfixed 
Product VersionDaily / GIT 
Target Version3.40Fixed in Version3.40 
Summary0005122: Security bug: JvEdit in password mode with Autohint = True allows to see password in hint
DescriptionSteps to reproduce:
* Place TJvEdit on form
* Make it narrow
* Set PasswordChar property to "*"
* Set AutoHint property to Enabled
* Set ShowHint property to Enabled
* run application
* enter long password, that will not fit in edit
* move mouse to TJvEdit

You can see your password in hint.

Solution:
change code to bypass autohint, when in password mode.
Additional InformationDemo project attached.
TagsNo tags attached.

Activities

2010-01-24 01:33

 

JvEditAutohintPassword_bug.zip (6,509 bytes)

obones

2010-03-08 15:30

administrator   ~0017244

This is now fixed in SVN

Issue History

Date Modified Username Field Change
2010-01-24 01:33 debose New Issue
2010-01-24 01:33 debose File Added: JvEditAutohintPassword_bug.zip
2010-03-08 15:30 obones Note Added: 0017244
2010-03-08 15:30 obones Assigned To => obones
2010-03-08 15:30 obones Status new => resolved
2010-03-08 15:30 obones Resolution open => fixed
2010-03-08 15:30 obones Fixed in Version => Daily / SVN
2010-03-08 15:30 obones Target Version => 3.40 - not yet released
2011-06-10 16:09 obones Fixed in Version Daily / SVN => 3.40