PT-1999-1842 · Netscape · Netscape

Published

1999-12-22

·

Updated

2022-08-17

·

CVE-2000-0034

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Netscape version 4.7
Description: The issue concerns the storage of user passwords in the preferences.js file during email sessions. Specifically, when using IMAP or POP, user passwords are recorded, regardless of the "remember passwords" setting.
Recommendations: For Netscape version 4.7, consider deleting the preferences.js file after each session or clearing the stored passwords manually to minimize the risk of password exposure. As a temporary workaround, avoid using the feature that automatically stores passwords until a more secure solution is implemented.

Fix

Related Identifiers

CVE-2000-0034

Affected Products

Netscape