CVE-2000-0034: Medium severity Netscape Communicator vulnerability
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Netscape Communicator 4.7from your environment.Uninstall Netscape Communicator 4.7 or stop using it if it is not required.
- Compensating control
Restrict access to the preferences.js file (and any backups) via filesystem permissions or ACLs so only the owning user/account and administrators can read it; consider isolating or blocking access to machines running Netscape Communicator 4.7 from untrusted networks.
- Operational
Inspect the user's preferences.js file and remove any stored password entries (delete lines that contain saved IMAP/POP passwords). After removing the entries, restart the client.
- Operational
Rotate (change) passwords for any IMAP or POP accounts that were used with Netscape Communicator 4.7, since those passwords may have been recorded and exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0034?
CVE-2000-0034 has been classified as a high severity vulnerability due to its potential to expose user passwords.
How do I fix CVE-2000-0034?
To fix CVE-2000-0034, users should upgrade their Netscape Navigator to a version later than 4.7 where this vulnerability is addressed.
What software is affected by CVE-2000-0034?
CVE-2000-0034 specifically affects Netscape Communicator version 4.7.
What are the risks associated with CVE-2000-0034?
The main risk associated with CVE-2000-0034 is the unauthorized access to user passwords stored in the preferences.js file.
Can CVE-2000-0034 be exploited remotely?
CVE-2000-0034 is not a remotely exploitable vulnerability, as it primarily involves local file access.