First published: Wed Jan 12 2000(Updated: )
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Navigator | ||
Netscape Communicator | =4.7 | |
=4.7 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0087 is considered moderate due to the potential for sensitive information leakage.
To fix CVE-2000-0087, ensure that SSL is enforced for IMAP connections in your Netscape Communicator settings.
CVE-2000-0087 affects Netscape Communicator version 4.7 and Netscape Navigator.
CVE-2000-0087 can be exploited by sniffing plaintext usernames and passwords over an unencrypted IMAP connection.
While CVE-2000-0087 was relevant in its time, modern security practices and software versions have largely mitigated its impact.