PT-2002-1439 · Gaim · Gaim

Published

2002-05-29

·

Updated

2016-10-18

·

CVE-2002-0377

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gaim version 0.57
Description The issue allows local users to access sensitive information, including MSN web email accounts of other users, by reading authentication data from files in the /tmp directory. This is possible because Gaim stores sensitive information in world-readable and group-writable files.
Recommendations For Gaim version 0.57, consider restricting access to the /tmp directory or modifying the file permissions to prevent unauthorized access until a patch is available. As a temporary workaround, avoid using Gaim to access MSN web email accounts until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0377

Affected Products

Gaim