PT-2002-2875 · Cerulean Studios · Trillian
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2162
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Cerulean Studios Trillian versions 0.73 and earlier
Description:
The issue concerns the use of weak encryption, specifically XOR, for storing user passwords in .ini files within the Trillian directory. This weakness allows local users to gain access to other user accounts.
Recommendations:
For versions 0.73 and earlier, consider updating the password storage mechanism to use a more secure encryption method to protect user passwords. As a temporary workaround, restrict access to the Trillian directory and .ini files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trillian