PT-2002-2875 · Cerulean Studios · Trillian

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2162

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Cerulean Studios Trillian versions 0.73 and earlier
Description: The issue concerns the use of weak encryption, specifically XOR, for storing user passwords in .ini files within the Trillian directory. This weakness allows local users to gain access to other user accounts.
Recommendations: For versions 0.73 and earlier, consider updating the password storage mechanism to use a more secure encryption method to protect user passwords. As a temporary workaround, restrict access to the Trillian directory and .ini files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2162

Produtos afetados

Trillian