PT-2002-2875 · Cerulean Studios · Trillian

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2162

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Cerulean Studios Trillian versions 0.73 and earlier
Description: The issue concerns the use of weak encryption, specifically XOR, for storing user passwords in .ini files within the Trillian directory. This weakness allows local users to gain access to other user accounts.
Recommendations: For versions 0.73 and earlier, consider updating the password storage mechanism to use a more secure encryption method to protect user passwords. As a temporary workaround, restrict access to the Trillian directory and .ini files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2162

Affected Products

Trillian