PT-2002-2406 · Newsreactor · Newsreactor
Published
2002-12-31
·
Updated
2024-02-14
·
CVE-2002-1682
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NewsReactor version 1.0
Description
The issue is related to a weak encryption scheme used by the software, which could allow local users to decrypt passwords and gain access to other users' newsgroup accounts.
Recommendations
For NewsReactor version 1.0, consider changing the encryption scheme to a stronger one to prevent local users from decrypting passwords and gaining unauthorized access to newsgroup accounts. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.
Exploit
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Newsreactor