OSVDB ID: 11565

Title: IceWarp WebMail Account Password Storage Weak Encryption

Info

Disclosure

Nov 05, 2004

Discovery

Unknown

Dates

Exploit

Nov 05, 2004

Solution

Unknown

Description

IceWarp Merak Mail Server with IceWarp Web Mail contains a flaw that may lead to an unauthorized password exposure. It is possible for a malicious user to gain access to weak encrypted passwords due to the insecure location of the 'settings.cfg', 'users.cfg', 'users.dat' and 'user.dat' configuration files, which may lead to a loss of confidentiality.

Classification

Location: Local Access Required
Attack Type: Cryptographic
Impact: Loss of Confidentiality
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

IceWarp, Ltd.

Merak Mail Server

7.6.0
7.5.2
7.6.4r

IceWarp Web Mail

5.3.0
5.2.8
5.3.2

References

Credit

  • ShineShadow - ss_contactsBrand New Doo Doohotmail.com -


Direct URL: http://osvdb.org/36218