First published: Sat May 15 1999(Updated: )
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pegasus Mail Transport System | <=3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1366 has a moderate severity rating due to weak encryption used for password storage.
To fix CVE-1999-1366, upgrade to a version of Pegasus Mail later than 3.0 which implements stronger encryption methods.
CVE-1999-1366 affects Pegasus Mail versions 3.0 and earlier.
CVE-1999-1366 compromises local POP3 passwords stored in the pmail.ini file, allowing unauthorized access.
Local users on the system can exploit CVE-1999-1366 as it allows decryption of passwords stored unsecurely.