PT-2002-2186 · Netscape · Netscape Communicator

Published

2002-11-21

·

Updated

2008-09-10

·

CVE-2002-1204

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Netscape Communicator versions 4.x
Description: The issue allows attackers to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password. This is achieved by redefining the user pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
Recommendations: For Netscape Communicator versions 4.x, consider restricting access to the prefs.js file as a temporary workaround until a patch is available. Additionally, avoid using the user pref() function in sensitive contexts to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1204

Affected Products

Netscape Communicator