CVE-1999-1002: Weak Encryption
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the option to save mail passwords in Netscape's mail preferences so passwords are not stored using the product's weak encryption.
Netscape Navigator / Communicator store_mail_passwords = false - Compensating control
Until a stronger storage mechanism or patch is available, restrict access to machines and user profile directories that contain Netscape stored credentials (limit local and network access, enforce filesystem permissions, and isolate affected hosts).
- Operational
Remove any stored Netscape mail passwords from user profiles (clear saved passwords or delete password storage files) and rotate/change the affected email account passwords.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1002?
CVE-1999-1002 has a high severity due to the use of weak encryption for passwords.
How do I fix CVE-1999-1002?
To fix CVE-1999-1002, upgrade to a newer version of Netscape Communicator that does not use weak encryption.
What versions of Netscape are affected by CVE-1999-1002?
CVE-1999-1002 specifically affects Netscape Communicator version 4.7.
What types of vulnerabilities does CVE-1999-1002 represent?
CVE-1999-1002 represents a cryptographic vulnerability related to weak password storage.
Can CVE-1999-1002 be exploited remotely?
CVE-1999-1002 can potentially be exploited if an attacker gains access to the user's encrypted password storage.