PT-1999-1686 · Pegasus · Pegasus
Publicado
1999-05-15
·
Atualizado
2016-10-18
·
CVE-1999-1366
CVSS v2.0
3.6
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Pegasus e-mail client versions 3.0 and earlier
Description:
The issue concerns the use of weak encryption to store POP3 passwords in the pmail.ini file. This weakness allows local users to easily decrypt the passwords, potentially enabling them to read e-mail.
Recommendations:
For versions 3.0 and earlier, consider updating the encryption method used to store POP3 passwords to a stronger alternative. As a temporary workaround, restrict access to the pmail.ini file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pegasus